CVE-2017-7848 — Injection in Mozilla Thunderbird
Severity
5.3MEDIUMNVD
EPSS
1.9%
top 16.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 14
Description
RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages7 packages
Also affects: Debian Linux 7.0, 8.0, 9.0, Enterprise Linux 6.0, 7.0, 7.3, 7.4, 7.5
🔴Vulnerability Details
4GHSA▶
GHSA-fpgh-654r-2xjr: RSS fields can inject new lines into the created email structure, modifying the message body↗2022-05-14
CVEList▶
CVE-2017-7848: RSS fields can inject new lines into the created email structure, modifying the message body↗2018-06-11
OSV▶
CVE-2017-7848: RSS fields can inject new lines into the created email structure, modifying the message body↗2018-06-11