CVE-2005-3402Mozilla Thunderbird vulnerability

2 documents2 sources
Severity
2.6LOWNVD
EPSS
0.1%
top 65.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 1
Latest updateMay 1

Description

The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authentication information without detection via a man-in-the-middle (MITM) attack that bypasses TLS authentication or downgrades CRAM-MD5 authentication to plain authentication.

CVSS vector

AV:N/AC:H/C:P/I:N/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/thunderbird1.0.5, 1.0.7+1

🔴Vulnerability Details

1
GHSA
GHSA-jjm6-fj35-q837: The SMTP client in Mozilla Thunderbird 12022-05-01