CVE-2017-7848Injection in Mozilla Thunderbird

CWE-74Injection9 documents8 sources
Severity
5.3MEDIUMNVD
EPSS
1.9%
top 16.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages7 packages

CVEListV5mozilla/thunderbirdunspecified52.5.2
NVDmozilla/thunderbird< 52.5.2
Debianmozilla/thunderbird< 1:52.5.2-1+3
Ubuntumozilla/thunderbird< 1:52.6.0+build1-0ubuntu0.14.04.1+1

Also affects: Debian Linux 7.0, 8.0, 9.0, Enterprise Linux 6.0, 7.0, 7.3, 7.4, 7.5

🔴Vulnerability Details

4
GHSA
GHSA-fpgh-654r-2xjr: RSS fields can inject new lines into the created email structure, modifying the message body2022-05-14
CVEList
CVE-2017-7848: RSS fields can inject new lines into the created email structure, modifying the message body2018-06-11
OSV
CVE-2017-7848: RSS fields can inject new lines into the created email structure, modifying the message body2018-06-11
OSV
thunderbird vulnerabilities2018-01-29

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2018-01-29
Red Hat
Mozilla: RSS Feed vulnerable to new line Injection2017-12-22
Debian
CVE-2017-7848: thunderbird - RSS fields can inject new lines into the created email structure, modifying the ...2017

💬Community

1
Bugzilla
CVE-2017-7848 Mozilla: RSS Feed vulnerable to new line Injection2018-01-02
CVE-2017-7848 — Injection in Mozilla Thunderbird | cvebase