When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text was interpreted as a MIME message and the first paragraph was always treated as an email header section. A digitally signed text from a different context, such as a signed GIT commit, could be used to spoof an email message. This vulnerability affects Thunderbird < 115.6.
2023-12-19T14:15:07.093
2024-11-21T08:37:15.787
Modified
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | thunderbird | < 115.6 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |
Operating System | debian | debian_linux | 12.0 | Yes |