ZeroHour

CVE-2017-7829

PoC
CVSS 3.0
5.3 medium
EPSS
2%p77
Published
()
Modified
Description

It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This vulnerability affects Thunderbird < 52.5.2.

Vendors
mozillaredhatdebiancanonical
Products
thunderbird, enterprise linux aus, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux workstation, debian linux, ubuntu linux
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news