CVE-2017-7847Sensitive Information Exposure in Mozilla Thunderbird

Severity
4.3MEDIUMNVD
EPSS
0.9%
top 24.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages6 packages

CVEListV5mozilla/thunderbirdunspecified52.5.2
NVDmozilla/thunderbird< 52.5.2
Debianmozilla/thunderbird< 1:52.5.2-1+3

Also affects: Debian Linux 7.0, 8.0, 9.0, Enterprise Linux 7.4, 7.5

🔴Vulnerability Details

4
GHSA
GHSA-jmgx-hhrr-ppmv: Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name2022-05-14
OSV
CVE-2017-7847: Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name2018-06-11
CVEList
CVE-2017-7847: Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name2018-06-11
OSV
thunderbird vulnerabilities2018-01-29

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2018-01-29
Red Hat
Mozilla: Local path string can be leaked from RSS feed2017-12-22
Debian
CVE-2017-7847: thunderbird - Crafted CSS in an RSS feed can leak and reveal local path strings, which may con...2017

💬Community

1
Bugzilla
CVE-2017-7847 Mozilla: Local path string can be leaked from RSS feed2018-01-02
CVE-2017-7847 — Sensitive Information Exposure | cvebase