CVE-2023-50762

When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text was interpreted as a MIME message and the first paragraph was always treated as an email header section. A digitally signed text from a different context, such as a signed GIT commit, could be used to spoof an email message. This vulnerability affects Thunderbird < 115.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*

History

29 Dec 2023, 13:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2023/12/msg00021.html -

22 Dec 2023, 11:13

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CWE NVD-CWE-noinfo
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1862625 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1862625 - Issue Tracking, Permissions Required
References () https://www.debian.org/security/2023/dsa-5582 - () https://www.debian.org/security/2023/dsa-5582 - Third Party Advisory
References () https://www.mozilla.org/security/advisories/mfsa2023-55/ - () https://www.mozilla.org/security/advisories/mfsa2023-55/ - Vendor Advisory
First Time Mozilla
Debian
Mozilla thunderbird
Debian debian Linux
CPE cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*

22 Dec 2023, 01:15

Type Values Removed Values Added
Summary
  • (es) Al procesar un payload PGP/MIME que contiene texto firmado digitalmente, el primer párrafo del texto nunca se mostró al usuario. Esto se debe a que el texto se interpretó como un mensaje MIME y el primer párrafo siempre se trató como una sección de encabezado de correo electrónico. Un texto firmado digitalmente de un contexto diferente, como un commit GIT firmada, podría usarse para falsificar un mensaje de correo electrónico. Esta vulnerabilidad afecta a Thunderbird &lt; 115.6.
References
  • () https://www.debian.org/security/2023/dsa-5582 -

19 Dec 2023, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-19 14:15

Updated : 2023-12-29 13:15


NVD link : CVE-2023-50762

Mitre link : CVE-2023-50762

CVE.ORG link : CVE-2023-50762


JSON object : View

Products Affected

mozilla

  • thunderbird

debian

  • debian_linux