When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encryption or signature status. After opening and viewing the attached message B, when returning to the display of message A, the message A might be shown with the security status of message B. This vulnerability affects Thunderbird < 91.9.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | May 9, 2022 | May 5, 2022 |
| Alpine Linux | — | Upgrade thunderbird | Aug 22, 2024 | Dec 22, 2022 |
| Centos_linux | — | Upgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfo | May 6, 2022 | May 5, 2022 |
| Debian | — | Upgrade thunderbird | May 24, 2022 | May 24, 2022 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade mail-client/thunderbird. | Aug 11, 2022 | Aug 10, 2022 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 91.9Upgrade to the latest version of Mozilla Thunderbird | May 6, 2022 | May 3, 2022 |
| Oracle_linux | — | Upgrade thunderbird | May 6, 2022 | May 3, 2022 |
| Redhat_linux | — | Upgrade thunderbird-debuginfoNo solution existsUpgrade thunderbird-debugsourceUpgrade thunderbird | May 6, 2022 | May 5, 2022 |
| Rocky_linux | — | Upgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsource | May 10, 2022 | May 6, 2022 |
| Suse | — | Upgrade MozillaThunderbird-translations-commonUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-other | Oct 26, 2022 | May 17, 2022 |
| Ubuntu | — | Upgrade thunderbird | May 24, 2022 | May 5, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub