PT-2022-3645 · Mozilla+8 · Thunderbird+8
Jonathan Von Niessen
·
Published
2022-05-31
·
Updated
2024-06-15
·
CVE-2022-1834
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Thunderbird versions prior to 91.10
Description
The issue arises when displaying the sender of an email, specifically if the sender name contains the Braille Pattern Blank space character multiple times. This could be exploited by an attacker to send an email with their digital signature, making it appear as if it came from an arbitrary sender email address chosen by the attacker. If the sender name starts with a false email address followed by many Braille space characters, the attacker's email address remains invisible. Thunderbird compares the invisible sender address with the signature's email address, and if the signing key or certificate is accepted, the email is shown as having a valid digital signature.
Recommendations
For Thunderbird versions prior to 91.10, update to version 91.10 or later to resolve the issue. As a temporary workaround, consider disabling the display of sender names that contain special characters, such as the Braille Pattern Blank space character, until a patch is available. Restrict access to emails with suspicious sender names to minimize the risk of exploitation. Avoid relying solely on digital signatures for email authentication until the issue is resolved. At the moment, there is no other information about additional mitigation measures.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Thunderbird
Ubuntu