Note:
This project will be discontinued after December 13, 2021. [more]
2020-05-22
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0.
Products | Ubuntu_linux, Thunderbird |
Type | Origin Validation Error (CWE-346) |
First patch | - None (likely due to unavailable code) |
Links |
• https://www.mozilla.org/security/advisories/mfsa2020-18/
• https://security.gentoo.org/glsa/202005-03 • https://bugzilla.mozilla.org/show_bug.cgi?id=1617370 • https://usn.ubuntu.com/4373-1/ |