CVE-2017-7848
published 2018-06-11CVE-2017-7848: RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.
PriorityP423medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
1.76%
75.5th percentile
RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | thunderbird | < thunderbird 1:52.5.2-1 (bookworm) | thunderbird 1:52.5.2-1 (bookworm) |
| mozilla | thunderbird | < 52.5.2 | 52.5.2 |
| mozilla | thunderbird | >= 0 < 1:52.5.2-1 | 1:52.5.2-1 |
| mozilla | thunderbird | >= 0 < 1:52.5.2-1 | 1:52.5.2-1 |
| mozilla | thunderbird | >= 0 < 1:52.5.2-1 | 1:52.5.2-1 |
| mozilla | thunderbird | >= 0 < 1:52.5.2-1 | 1:52.5.2-1 |
| mozilla | thunderbird | >= 0 < 1:52.6.0+build1-0ubuntu0.14.04.1 | 1:52.6.0+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.6.0+build1-0ubuntu0.16.04.1 | 1:52.6.0+build1-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= unspecified < 52.5.2 | 52.5.2 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fpgh-654r-2xjr: RSS fields can inject new lines into the created email structure, modifying the message body
ghsa_unreviewed·2022-05-14
CVE-2017-7848 [MEDIUM] CWE-74 GHSA-fpgh-654r-2xjr: RSS fields can inject new lines into the created email structure, modifying the message body
RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.
OSV
CVE-2017-7848: RSS fields can inject new lines into the created email structure, modifying the message body
osv·2018-06-11·CVSS 5.3
CVE-2017-7848 [MEDIUM] CVE-2017-7848: RSS fields can inject new lines into the created email structure, modifying the message body
RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.
OSV
thunderbird vulnerabilities
osv·2018-01-29·CVSS 5.3
CVE-2017-7829 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
It was discovered that a From address encoded with a null character is
cut off in the message header display. An attacker could potentially
exploit this to spoof the sender address. (CVE-2017-7829)
It was discovered that it is possible to execute JavaScript in RSS feeds
in some circumstances. If a user were tricked in to opening a specially
crafted RSS feed, an attacker could potentially exploit this in
combination with another vulnerability, in order to cause unspecified
problems. (CVE-2017-7846)
It was discovered that the RSS feed can leak local path names. If a user
were tricked in to opening a specially crafted RSS feed, an attacker
could potentially exploit this to obtain sensitive information.
(CVE-2017-7847)
It was discovered that RSS feeds are vulner
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2018-01-29·CVSS 5.3
CVE-2017-7829 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
It was discovered that a From address encoded with a null character is
cut off in the message header display. An attacker could potentially
exploit this to spoof the sender address. (CVE-2017-7829)
It was discovered that it is possible to execute JavaScript in RSS feeds
in some circumstances. If a user were tricked in to opening a specially
crafted RSS feed, an attacker could potentially exploit this in
combination with another vulnerability, in order to cause unspecified
problems. (CVE-2017-7846)
It was discovered that the RSS feed can leak local path names. If a user
were tricked in to opening a specially crafted RSS feed, an attacker
could potentially exploit this to obtain sensitive infor
Red Hat
Mozilla: RSS Feed vulnerable to new line Injection
vendor_redhat·2017-12-22·CVSS 5.3
CVE-2017-7848 [MEDIUM] Mozilla: RSS Feed vulnerable to new line Injection
Mozilla: RSS Feed vulnerable to new line Injection
RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.
Debian
CVE-2017-7848: thunderbird - RSS fields can inject new lines into the created email structure, modifying the ...
vendor_debian·2017·CVSS 5.3
CVE-2017-7848 [MEDIUM] CVE-2017-7848: thunderbird - RSS fields can inject new lines into the created email structure, modifying the ...
RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.
Scope: local
bookworm: resolved (fixed in 1:52.5.2-1)
bullseye: resolved (fixed in 1:52.5.2-1)
forky: resolved (fixed in 1:52.5.2-1)
sid: resolved (fixed in 1:52.5.2-1)
trixie: resolved (fixed in 1:52.5.2-1)
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/102258http://www.securitytracker.com/id/1040123https://access.redhat.com/errata/RHSA-2018:0061https://bugzilla.mozilla.org/show_bug.cgi?id=1411699https://lists.debian.org/debian-lts-announce/2017/12/msg00026.htmlhttps://www.debian.org/security/2017/dsa-4075https://www.mozilla.org/security/advisories/mfsa2017-30/http://www.securityfocus.com/bid/102258http://www.securitytracker.com/id/1040123https://access.redhat.com/errata/RHSA-2018:0061https://bugzilla.mozilla.org/show_bug.cgi?id=1411699https://lists.debian.org/debian-lts-announce/2017/12/msg00026.htmlhttps://www.debian.org/security/2017/dsa-4075https://www.mozilla.org/security/advisories/mfsa2017-30/
2018-06-11
Published