ZeroHour

CVE-2018-5170

CVSS 3.0
4.3 medium
EPSS
2%p77
Published
()
Modified
Description

It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

Vendors
redhatmozilladebiancanonical
Products
enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, thunderbird, thunderbird esr, debian linux, ubuntu linux
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.