OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird versions from 68 to 102.9.1 were affected by this bug. This vulnerability affects Thunderbird < 102.10.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | Apr 21, 2023 | Apr 17, 2023 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade thunderbird-debuginfo | May 3, 2023 | May 3, 2023 |
| Centos_linux | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Apr 18, 2023 | Apr 17, 2023 |
| Debian | — | Upgrade thunderbird | Apr 24, 2023 | Apr 24, 2023 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 102.10 | Apr 12, 2023 | Apr 11, 2023 |
| Oracle_linux | — | Upgrade thunderbird | Apr 18, 2023 | Apr 11, 2023 |
| Redhat_linux | — | Upgrade thunderbirdUpgrade thunderbird-debugsourceNo solution existsUpgrade thunderbird-debuginfo | Apr 18, 2023 | Apr 17, 2023 |
| Rocky_linux | — | Upgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfo | Mar 12, 2024 | Jun 2, 2023 |
| Suse | — | Upgrade mozillathunderbird-translations-otherUpgrade mozillathunderbirdUpgrade mozillathunderbird-translations-common | May 1, 2023 | Apr 28, 2023 |
| Ubuntu | — | Upgrade thunderbird | Apr 17, 2023 | Apr 13, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub