CVE-2017-7848: Medium severity thunderbird vulnerability
Published Dec 22, 2017
·Updated
Last updated 24 July 2024
Other sources
RSS fields can inject new lines into the created email structure, modifying the message body.
— Red Hat
Affected Software
19 affected componentsFixes available
debian/thunderbird
1:115.12.0-1~deb11u11:115.16.0esr-1~deb11u11:115.12.0-1~deb12u11:115.16.0esr-1~deb12u11:128.2.0esr-11:128.3.0esr-1
Mozilla Thunderbird<52.5.2
52.5.2
Mozilla Thunderbird<52.5.2
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.3
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Eus=7.3
redhat Enterprise Linux Server Eus=7.4
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Workstation=6.0
redhat Enterprise Linux Workstation=7.0
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Dec 22, 2017
CVE Published
12:00 AM
Jan 2, 2018
Data Sourced
via Red Hat·08:57 AM
DescriptionSeverityAffected Software
Jun 11, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·10:41 PM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·10:48 PM
RemedyDescriptionSeverityAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is CVE-2017-7848?
CVE-2017-7848 is a vulnerability that allows RSS fields to inject new lines into the created email structure, modifying the message body.
2
Which software versions are affected by CVE-2017-7848?
CVE-2017-7848 affects Thunderbird versions before 52.6.0.
3
What is the severity of CVE-2017-7848?
CVE-2017-7848 has a severity rating of medium with a CVSS score of 5.3.
4
How can I fix CVE-2017-7848?
To fix CVE-2017-7848, it is recommended to update Thunderbird to version 52.6.0 or newer.
5
Where can I find more information about CVE-2017-7848?
You can find more information about CVE-2017-7848 on the Mozilla Bugzilla and Mozilla Security Advisories websites.