CVE-2017-7829: Input Validation
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string.
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2017-7829?
CVE-2017-7829 is a vulnerability that allows the spoofing of the sender's email address and displaying an arbitrary sender address to the email recipient in Thunderbird.
Which software is affected by CVE-2017-7829?
Thunderbird versions < 52.5.2 are affected by CVE-2017-7829.
What is the severity of CVE-2017-7829?
The severity of CVE-2017-7829 is medium, with a CVSS score of 5.3.
How can I fix CVE-2017-7829?
To fix CVE-2017-7829, upgrade Thunderbird to version 52.6.0 or higher.
Where can I find more information about CVE-2017-7829?
You can find more information about CVE-2017-7829 at the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1423432), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2017-30/), [SecurityFocus](http://www.securityfocus.com/bid/102258).