Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7h9q-985f-8xvm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.

EPSS

Процентиль: 23%
0.00071
Низкий

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 2.5
ubuntu
около 4 лет назад

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.

CVSS3: 2.5
redhat
больше 4 лет назад

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.

CVSS3: 2.5
nvd
около 4 лет назад

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.

CVSS3: 2.5
debian
около 4 лет назад

Signatures are written to disk before and read during verification, wh ...

CVSS3: 7.8
fstec
больше 4 лет назад

Уязвимость почтового клиента Thunderbird, вызванная ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 23%
0.00071
Низкий

Дефекты

CWE-362