CVE-2017-7829

MEDIUM

Description

It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This vulnerability affects Thunderbird < 52.5.2.

References

http://www.securityfocus.com/bid/102258

http://www.securitytracker.com/id/1040123

https://access.redhat.com/errata/RHSA-2018:0061

https://bugzilla.mozilla.org/show_bug.cgi?id=1423432

https://lists.debian.org/debian-lts-announce/2017/12/msg00026.html

https://usn.ubuntu.com/3529-1/

https://www.debian.org/security/2017/dsa-4075

https://www.mozilla.org/security/advisories/mfsa2017-30/

Details

Source: MITRE

Published: 2018-06-11

Updated: 2018-08-07

Type: CWE-20

Risk Information

CVSS v2.0

Base Score: 5

Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N)

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3.0

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Impact Score: 1.4

Exploitability Score: 3.9

Severity: MEDIUM