CVE-2017-7847
published 2018-06-11CVE-2017-7847: Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2.
PriorityP417medium4.3CVSS 3.0
AVNACLPRNUIRSUCLINAN
EPSS
1.65%
74.0th percentile
Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | thunderbird | < thunderbird 1:52.5.2-1 (bookworm) | thunderbird 1:52.5.2-1 (bookworm) |
| mozilla | thunderbird | < 52.5.2 | 52.5.2 |
| mozilla | thunderbird | >= 0 < 1:52.5.2-1 | 1:52.5.2-1 |
| mozilla | thunderbird | >= 0 < 1:52.5.2-1 | 1:52.5.2-1 |
| mozilla | thunderbird | >= 0 < 1:52.5.2-1 | 1:52.5.2-1 |
| mozilla | thunderbird | >= 0 < 1:52.5.2-1 | 1:52.5.2-1 |
| mozilla | thunderbird | >= 0 < 1:52.6.0+build1-0ubuntu0.14.04.1 | 1:52.6.0+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.6.0+build1-0ubuntu0.16.04.1 | 1:52.6.0+build1-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= unspecified < 52.5.2 | 52.5.2 |
| redhat | enterprise_linux_aus | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_ubuntu5.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2018-01-29·CVSS 5.3
CVE-2017-7829 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
It was discovered that a From address encoded with a null character is
cut off in the message header display. An attacker could potentially
exploit this to spoof the sender address. (CVE-2017-7829)
It was discovered that it is possible to execute JavaScript in RSS feeds
in some circumstances. If a user were tricked in to opening a specially
crafted RSS feed, an attacker could potentially exploit this in
combination with another vulnerability, in order to cause unspecified
problems. (CVE-2017-7846)
It was discovered that the RSS feed can leak local path names. If a user
were tricked in to opening a specially crafted RSS feed, an attacker
could potentially exploit this to obtain sensitive infor
Red Hat
Mozilla: Local path string can be leaked from RSS feed
vendor_redhat·2017-12-22·CVSS 4.3
CVE-2017-7847 [MEDIUM] Mozilla: Local path string can be leaked from RSS feed
Mozilla: Local path string can be leaked from RSS feed
Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2.
Debian
CVE-2017-7847: thunderbird - Crafted CSS in an RSS feed can leak and reveal local path strings, which may con...
vendor_debian·2017·CVSS 4.3
CVE-2017-7847 [MEDIUM] CVE-2017-7847: thunderbird - Crafted CSS in an RSS feed can leak and reveal local path strings, which may con...
Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2.
Scope: local
bookworm: resolved (fixed in 1:52.5.2-1)
bullseye: resolved (fixed in 1:52.5.2-1)
forky: resolved (fixed in 1:52.5.2-1)
sid: resolved (fixed in 1:52.5.2-1)
trixie: resolved (fixed in 1:52.5.2-1)
GHSA
GHSA-jmgx-hhrr-ppmv: Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name
ghsa_unreviewed·2022-05-14
CVE-2017-7847 [MEDIUM] CWE-200 GHSA-jmgx-hhrr-ppmv: Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name
Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2.
OSV
CVE-2017-7847: Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name
osv·2018-06-11·CVSS 4.3
CVE-2017-7847 [MEDIUM] CVE-2017-7847: Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name
Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2.
OSV
thunderbird vulnerabilities
osv·2018-01-29·CVSS 5.3
CVE-2017-7829 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
It was discovered that a From address encoded with a null character is
cut off in the message header display. An attacker could potentially
exploit this to spoof the sender address. (CVE-2017-7829)
It was discovered that it is possible to execute JavaScript in RSS feeds
in some circumstances. If a user were tricked in to opening a specially
crafted RSS feed, an attacker could potentially exploit this in
combination with another vulnerability, in order to cause unspecified
problems. (CVE-2017-7846)
It was discovered that the RSS feed can leak local path names. If a user
were tricked in to opening a specially crafted RSS feed, an attacker
could potentially exploit this to obtain sensitive information.
(CVE-2017-7847)
It was discovered that RSS feeds are vulner
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/102258http://www.securitytracker.com/id/1040123https://access.redhat.com/errata/RHSA-2018:0061https://bugzilla.mozilla.org/show_bug.cgi?id=1411708https://lists.debian.org/debian-lts-announce/2017/12/msg00026.htmlhttps://www.debian.org/security/2017/dsa-4075https://www.mozilla.org/security/advisories/mfsa2017-30/http://www.securityfocus.com/bid/102258http://www.securitytracker.com/id/1040123https://access.redhat.com/errata/RHSA-2018:0061https://bugzilla.mozilla.org/show_bug.cgi?id=1411708https://lists.debian.org/debian-lts-announce/2017/12/msg00026.htmlhttps://www.debian.org/security/2017/dsa-4075https://www.mozilla.org/security/advisories/mfsa2017-30/
2018-06-11
Published