Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5170

Опубликовано: 11 июн. 2018
Источник: debian

Описание

It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
thunderbirdfixed1:52.8.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-13/#CVE-2018-5170

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 7 лет назад

It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

CVSS3: 4.2
redhat
больше 7 лет назад

It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

CVSS3: 4.3
nvd
больше 7 лет назад

It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

CVSS3: 4.3
github
больше 3 лет назад

It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

CVSS3: 4.3
fstec
больше 7 лет назад

Уязвимость почтового клиента Thunderbird, существующая из-за недостаточной проверки входных данных, позволяющая нарушителю отобразить произвольное имя вложения