CVE-2022-1520: Medium severity thunderbird vulnerability
When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encryption or signature status. After opening and viewing the attached message B, when returning to the display of message A, the message A might be shown with the security status of message B.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-1520?
CVE-2022-1520 is a vulnerability in Thunderbird that may show an incorrect encryption or signature status when viewing an email message with an attached encrypted or digitally signed message.
How does CVE-2022-1520 affect Thunderbird?
CVE-2022-1520 affects Thunderbird by displaying incorrect encryption or signature status when viewing email messages with attached encrypted or digitally signed messages.
What is the severity of CVE-2022-1520?
CVE-2022-1520 has a severity level of medium, with a CVSS score of 4.3.
How can I fix CVE-2022-1520?
To fix CVE-2022-1520, update Thunderbird to version 91.9 or later.
Where can I find more information about CVE-2022-1520?
You can find more information about CVE-2022-1520 at the following references: [1] [2] [3]