REDHAT-BUG-2366287: High severity thunderbird vulnerability
Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From header contains an (invalid) value "Spoofed Name ", Thunderbird treats spoofed as the actual address. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2366287?
The REDHAT-BUG-2366287 vulnerability is classified as a security vulnerability that allows sender spoofing.
How does REDHAT-BUG-2366287 affect Thunderbird?
REDHAT-BUG-2366287 affects Thunderbird by permitting invalid From addresses to be treated as legitimate, enabling sender spoofing.
What versions of Thunderbird are affected by REDHAT-BUG-2366287?
Mozilla Thunderbird versions up to 128.10.1 and 138.0.1 are affected by REDHAT-BUG-2366287.
How can I mitigate the risks associated with REDHAT-BUG-2366287?
To mitigate the risks of REDHAT-BUG-2366287, users should update to the latest available version of Thunderbird.
What kind of attacks can exploit REDHAT-BUG-2366287?
REDHAT-BUG-2366287 can be exploited in phishing attacks where an attacker uses spoofed email addresses to deceive recipients.