Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-3417

Опубликовано: 24 июл. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

released

1:102.13.0+build1-0ubuntu1
esm-infra/focal

DNE

focal

released

1:102.15.0+build1-0ubuntu0.20.04.1
jammy

released

1:102.15.0+build1-0ubuntu0.22.04.1
lunar

released

1:102.15.0+build1-0ubuntu0.23.04.1
mantic

released

1:102.13.0+build1-0ubuntu1
noble

released

1:102.13.0+build1-0ubuntu1
trusty

ignored

end of standard support
upstream

released

1:102.13.1-1

Показывать по

EPSS

Процентиль: 38%
0.00161
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 2 года назад

Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1.

CVSS3: 7.5
nvd
почти 2 года назад

Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1.

CVSS3: 7.5
debian
почти 2 года назад

Thunderbird allowed the Text Direction Override Unicode Character in f ...

CVSS3: 7.5
github
почти 2 года назад

Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1.

CVSS3: 8.1
fstec
почти 2 года назад

Уязвимость почтового клиента Thunderbird, существующая из-за неправильной обработки символа Unicode для переопределения направления текста в именах файлов, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 38%
0.00161
Низкий

7.5 High

CVSS3