CVE-2020-12397

Description

By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0.

Risk Information

Base Score
4.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS Score
Exploitation Probability
0.197

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in Mozilla Thunderbird (68.8.0)Windows
Multiple vulnerabilities fixed in Mozilla Thunderbird (x64) (68.8.0)Windows
Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (68.8.0)Mac
Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (68.8.1)Mac
Multiple Vulnerabilities are affected in Mozilla Thunderbird for Mac 68.7.0Mac
thunderbird security update(DSA-4683-1) thunderbird_68.8.0-1~deb9u1_i386.debLinux
thunderbird security update(DSA-4683-1) thunderbird_68.8.0-1~deb9u1_amd64.debLinux
thunderbird security update(DSA-4683-1) thunderbird_68.8.0-1~deb10u1_i386.debLinux
thunderbird security update(DSA-4683-1) thunderbird_68.8.0-1~deb10u1_amd64.debLinux
(RHSA-2020:2050) thunderbird security update thunderbird-68.8.0-1.el7_8.x86_64.rpmLinux
(RHSA-2020:2046) thunderbird security update thunderbird-68.8.0-1.el8_2.x86_64.rpmLinux
(RHSA-2020:2046) thunderbird security update thunderbird-debugsource-68.8.0-1.el8_2.x86_64.rpmLinux
(RHSA-2020:2049) thunderbird security update thunderbird-68.8.0-1.el6_10.i686.rpmLinux
(RHSA-2020:2049) thunderbird security update thunderbird-68.8.0-1.el6_10.x86_64.rpmLinux
Mozilla Open Source mail and newsgroup client (USN-4373-1) thunderbird_68.8.0+build2-0ubuntu0.16.04.2_i386.debLinux
Mozilla Open Source mail and newsgroup client (USN-4373-1) thunderbird_68.8.0+build2-0ubuntu0.16.04.2_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-4373-1) thunderbird_68.8.0+build2-0ubuntu0.18.04.2_i386.debLinux
Mozilla Open Source mail and newsgroup client (USN-4373-1) thunderbird_68.8.0+build2-0ubuntu0.18.04.2_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-4373-1) thunderbird_68.8.0+build2-0ubuntu0.19.10.2_i386.debLinux
Mozilla Open Source mail and newsgroup client (USN-4373-1) thunderbird_68.8.0+build2-0ubuntu0.19.10.2_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-4373-1) thunderbird_68.8.0+build2-0ubuntu0.20.04.2_amd64.debLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-314106Mozilla Thunderbird (68.8.0)
PATCH-314107Mozilla Thunderbird (x64) (68.8.0)
PATCH-611353Mozilla Thunderbird For Mac (128.12.0)
PATCH-611353Mozilla Thunderbird For Mac (128.12.0)
PATCH-611807Mozilla Thunderbird For Mac (142.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234