CVE-2018-5170: Input Validation
It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-5170?
CVE-2018-5170 is a vulnerability that allows spoofing the filename of an attachment and displaying an arbitrary attachment name, potentially leading to a user opening a remote attachment that is a different file type than expected.
Which software versions are affected by CVE-2018-5170?
CVE-2018-5170 affects Thunderbird ESR versions earlier than 52.8 and Thunderbird versions earlier than 52.8.
How can the CVE-2018-5170 vulnerability be exploited?
The CVE-2018-5170 vulnerability can be exploited by spoofing the filename of an attachment and tricking the user into opening it, which may lead to the execution of malicious code or revealing sensitive information.
What is the severity of CVE-2018-5170?
CVE-2018-5170 has a severity rating of medium with a CVSS score of 4.0.
How can I fix the CVE-2018-5170 vulnerability?
To fix the CVE-2018-5170 vulnerability, it is recommended to update Thunderbird to version 52.8 or higher.