CVE-2023-0547
published 2023-06-02CVE-2023-0547: OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird…
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.37%
29.9th percentile
OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird versions from 68 to 102.9.1 were affected by this bug. This vulnerability affects Thunderbird < 102.10.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:102.10.0-1 (bookworm) | thunderbird 1:102.10.0-1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | >= 0 < 1:102.10.0-1~deb11u1 | 1:102.10.0-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0-1 | 1:102.10.0-1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0-1 | 1:102.10.0-1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0-1 | 1:102.10.0-1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0+build2-0ubuntu0.18.04.1 | 1:102.10.0+build2-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0+build2-0ubuntu0.20.04.1 | 1:102.10.0+build2-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0+build2-0ubuntu0.22.04.1 | 1:102.10.0+build2-0ubuntu0.22.04.1 |
| mozilla | thunderbird | >= 68.0 < 102.10 | 102.10 |
| mozilla | thunderbird | >= unspecified < 102.10 | 102.10 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2023-04-13·CVSS 6.5
CVE-2023-29535 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-1945, CVE-2023-29548,
CVE-2023-29550)
Paul Menzel discovered that Thunderbird did not properly validate OCSP
revocation status of recipient certificates when sending S/Mime encrypted
email. An attacker could potentially exploits this issue to perform
spoofing attack. (CVE-2023-0547)
Ribose RNP Team discovered that Thunderbird did not properly manage memory
when pa
Red Hat
Thunderbird: Revocation status of S/Mime recipient certificates was not checked
vendor_redhat·2023-04-11·CVSS 6.5
CVE-2023-0547 [MEDIUM] CWE-356 Thunderbird: Revocation status of S/Mime recipient certificates was not checked
Thunderbird: Revocation status of S/Mime recipient certificates was not checked
OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird versions from 68 to 102.9.1 were affected by this bug. This vulnerability affects Thunderbird < 102.10.
The Mozilla Foundation Security Advisory describes this flaw as:
OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird versions from 68 to 102.9.1 were affected by this bug.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: thunderbird (Red Hat Enterprise Linux 6)
Debian
CVE-2023-0547: thunderbird - OCSP revocation status of recipient certificates was not checked when sending S/...
vendor_debian·2023·CVSS 6.5
CVE-2023-0547 [MEDIUM] CVE-2023-0547: thunderbird - OCSP revocation status of recipient certificates was not checked when sending S/...
OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird versions from 68 to 102.9.1 were affected by this bug. This vulnerability affects Thunderbird < 102.10.
Scope: local
bookworm: resolved (fixed in 1:102.10.0-1)
bullseye: resolved (fixed in 1:102.10.0-1~deb11u1)
forky: resolved (fixed in 1:102.10.0-1)
sid: resolved (fixed in 1:102.10.0-1)
trixie: resolved (fixed in 1:102.10.0-1)
Mozilla
Mozilla Foundation Security Advisory 2023-15: CVE-2023-0547
vendor_mozilla·CVSS 6.5
CVE-2023-0547 [MEDIUM] Mozilla Foundation Security Advisory 2023-15: CVE-2023-0547
Mozilla Foundation Security Advisory 2023-15
CVE: CVE-2023-0547
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 102.10
OSV
CVE-2023-0547: OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted
osv·2023-06-02·CVSS 6.5
CVE-2023-0547 [MEDIUM] CVE-2023-0547: OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted
OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird versions from 68 to 102.9.1 were affected by this bug. This vulnerability affects Thunderbird < 102.10.
GHSA
GHSA-r9gq-fgfv-3p2p: OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted
ghsa_unreviewed·2023-06-02
CVE-2023-0547 [MEDIUM] CWE-295 GHSA-r9gq-fgfv-3p2p: OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted
OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird versions from 68 to 102.9.1 were affected by this bug. This vulnerability affects Thunderbird < 102.10.
OSV
thunderbird vulnerabilities
osv·2023-04-13·CVSS 6.5
CVE-2023-1945 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-1945, CVE-2023-29548,
CVE-2023-29550)
Paul Menzel discovered that Thunderbird did not properly validate OCSP
revocation status of recipient certificates when sending S/Mime encrypted
email. An attacker could potentially exploits this issue to perform
spoofing attack. (CVE-2023-0547)
Ribose RNP Team discovered that Thunderbird did not properly manage memory
when parsing certain OpenPGP messages. An attacker could potentially
exploi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-02
Published