CVE Vulnerabilities

CVE-2020-12397

Origin Validation Error

Published: May 22, 2020 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
4.3 LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

NameVendorStart VersionEnd Version
ThunderbirdMozilla*68.8.0 (excluding)
Red Hat Enterprise Linux 6RedHatthunderbird-0:68.8.0-1.el6_10*
Red Hat Enterprise Linux 7RedHatthunderbird-0:68.8.0-1.el7_8*
Red Hat Enterprise Linux 8RedHatthunderbird-0:68.8.0-1.el8_2*
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsRedHatthunderbird-0:68.8.0-1.el8_0*
Red Hat Enterprise Linux 8.1 Extended Update SupportRedHatthunderbird-0:68.8.0-1.el8_1*
ThunderbirdUbuntubionic*
ThunderbirdUbuntudevel*
ThunderbirdUbuntueoan*
ThunderbirdUbuntufocal*
ThunderbirdUbuntutrusty*
ThunderbirdUbuntuupstream*
ThunderbirdUbuntuxenial*

References