Severity
6.5MEDIUMNVD
EPSS
0.2%
top 61.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22
Latest updateOct 1

Description

When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would have displayed all the spaces. This could have been used by an attacker to send an email message with the attacker's digital signature, that was shown with an arbitrary sender email address chosen by the attacker. If the sender name started with a false email address, followed by many Braille space characters, the attacker's email address was not visib

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

debiandebian/thunderbird< thunderbird 1:91.10.0-1 (bookworm)
CVEListV5mozilla/thunderbirdunspecified91.10
NVDmozilla/thunderbird< 91.10
Debianmozilla/thunderbird< 1:91.10.0-1~deb11u1+3
Ubuntumozilla/thunderbird< 1:91.11.0+build2-0ubuntu0.18.04.1+2

🔴Vulnerability Details

3
GHSA
GHSA-qq6h-hx9q-4fxv: When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would have2022-12-22
OSV
CVE-2022-1834: When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would have2022-12-22
OSV
thunderbird vulnerabilities2022-07-14

📋Vendor Advisories

5
Red Hat
kernel: mmc: vub300: fix warning - do not call blocking ops when !TASK_RUNNING2025-10-01
Ubuntu
Thunderbird vulnerabilities2022-07-14
Red Hat
Mozilla: Braille space character caused incorrect sender email to be shown for a digitally signed email2022-05-31
Debian
CVE-2022-1834: thunderbird - When displaying the sender of an email, and the sender name contained the Braill...2022
Mozilla
Mozilla Foundation Security Advisory 2022-22: CVE-2022-1834