CVE-2022-2226
published 2022-12-22CVE-2022-2226: An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature…
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.41%
33.5th percentile
An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email's date will be shown. If the dates were different, then Thunderbird didn't report the email as having an invalid signature. If an attacker performed a replay attack, in which an old email with old contents are resent at a later time, it could lead the victim to believe that the statements in the email are current. Fixed versions of Thunderbird will require that the signature's date roughly matches the displayed date of the email. This vulnerability affects Thunderbird < 102 and Thunderbird < 91.11.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:91.11.0-1 (bookworm) | thunderbird 1:91.11.0-1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 91.11 | 91.11 |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | >= 0 < 1:91.11.0-1~deb11u1 | 1:91.11.0-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:91.11.0-1 | 1:91.11.0-1 |
| mozilla | thunderbird | >= 0 < 1:91.11.0-1 | 1:91.11.0-1 |
| mozilla | thunderbird | >= 0 < 1:91.11.0-1 | 1:91.11.0-1 |
| mozilla | thunderbird | >= 0 < 1:91.11.0+build2-0ubuntu0.18.04.1 | 1:91.11.0+build2-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= 0 < 1:91.11.0+build2-0ubuntu0.20.04.1 | 1:91.11.0+build2-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= 0 < 1:91.11.0+build2-0ubuntu0.22.04.1 | 1:91.11.0+build2-0ubuntu0.22.04.1 |
| mozilla | thunderbird | >= unspecified < 102 | 102 |
| mozilla | thunderbird | >= unspecified < 91.11 | 91.11 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2022-07-14·CVSS 6.5
CVE-2022-34468 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, spoof the UI, bypass CSP restrictions, or
execute arbitrary code. (CVE-2022-2200, CVE-2022-31736, CVE-2022-31737,
CVE-2022-31738, CVE-2022-31740, CVE-2022-31741, CVE-2022-31742,
CVE-2022-31744, CVE-2022-31747, CVE-2022-34468, CVE-2022-34470,
CVE-2022-34479, CVE-2022-34481, CVE-2022-34484)
It was discovered that an unavailable PAC file caused OCSP requests to
be blocked, resulting in incorrect error pages being displayed.
(CVE-2022-34472)
It was disc
Red Hat
Mozilla: An email with a mismatching OpenPGP signature date was accepted as valid
vendor_redhat·2022-06-28·CVSS 6.5
CVE-2022-2226 [MEDIUM] CWE-357 Mozilla: An email with a mismatching OpenPGP signature date was accepted as valid
Mozilla: An email with a mismatching OpenPGP signature date was accepted as valid
An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email's date will be shown. If the dates were different, then Thunderbird didn't report the email as having an invalid signature. If an attacker performed a replay attack, in which an old email with old contents are resent at a later time, it could lead the victim to believe that the statements in the email are current. Fixed versions of Thunderbird will require that the signature's date roughly matches the displayed date of the email. This vulnerability affects Thunderbird < 102 and Thunderbird < 91.11.
A flaw was found in Mozilla. The Mozilla Foun
Debian
CVE-2022-2226: thunderbird - An OpenPGP digital signature includes information about the date when the signat...
vendor_debian·2022·CVSS 6.5
CVE-2022-2226 [MEDIUM] CVE-2022-2226: thunderbird - An OpenPGP digital signature includes information about the date when the signat...
An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email's date will be shown. If the dates were different, then Thunderbird didn't report the email as having an invalid signature. If an attacker performed a replay attack, in which an old email with old contents are resent at a later time, it could lead the victim to believe that the statements in the email are current. Fixed versions of Thunderbird will require that the signature's date roughly matches the displayed date of the email. This vulnerability affects Thunderbird < 102 and Thunderbird < 91.11.
Scope: local
bookworm: resolved (fixed in 1:91.11.0-1)
bullseye: resolved (fixed in 1:91.11.0-1~deb11u1)
forky: resolved (fixed i
Mozilla
Mozilla Foundation Security Advisory 2022-26: CVE-2022-2226
vendor_mozilla·CVSS 6.5
CVE-2022-2226 [MEDIUM] Mozilla Foundation Security Advisory 2022-26: CVE-2022-2226
Mozilla Foundation Security Advisory 2022-26
CVE: CVE-2022-2226
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 102
Thunderbird 91.11
OSV
CVE-2022-2226: An OpenPGP digital signature includes information about the date when the signature was created
osv·2022-12-22·CVSS 6.5
CVE-2022-2226 [MEDIUM] CVE-2022-2226: An OpenPGP digital signature includes information about the date when the signature was created
An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email's date will be shown. If the dates were different, then Thunderbird didn't report the email as having an invalid signature. If an attacker performed a replay attack, in which an old email with old contents are resent at a later time, it could lead the victim to believe that the statements in the email are current. Fixed versions of Thunderbird will require that the signature's date roughly matches the displayed date of the email. This vulnerability affects Thunderbird < 102 and Thunderbird < 91.11.
GHSA
GHSA-g426-wcxv-272f: An OpenPGP digital signature includes information about the date when the signature was created
ghsa_unreviewed·2022-12-22
CVE-2022-2226 [MEDIUM] CWE-294 GHSA-g426-wcxv-272f: An OpenPGP digital signature includes information about the date when the signature was created
An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email's date will be shown. If the dates were different, then Thunderbird didn't report the email as having an invalid signature. If an attacker performed a replay attack, in which an old email with old contents are resent at a later time, it could lead the victim to believe that the statements in the email are current. Fixed versions of Thunderbird will require that the signature's date roughly matches the displayed date of the email. This vulnerability affects Thunderbird < 102 and Thunderbird < 91.11.
OSV
thunderbird vulnerabilities
osv·2022-07-14·CVSS 6.5
CVE-2022-2200 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, spoof the UI, bypass CSP restrictions, or
execute arbitrary code. (CVE-2022-2200, CVE-2022-31736, CVE-2022-31737,
CVE-2022-31738, CVE-2022-31740, CVE-2022-31741, CVE-2022-31742,
CVE-2022-31744, CVE-2022-31747, CVE-2022-34468, CVE-2022-34470,
CVE-2022-34479, CVE-2022-34481, CVE-2022-34484)
It was discovered that an unavailable PAC file caused OCSP requests to
be blocked, resulting in incorrect error pages being displayed.
(CVE-2022-34472)
It was discovered that the Braille space character could be used to
cause Thund
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-22
Published