CVE-2023-0430
Summary
| CVE | CVE-2023-0430 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-02 17:15:00 UTC |
| Updated | 2023-06-09 17:02:00 UTC |
| Description | Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as having a valid signature. Thunderbird versions from 68 to 102.7.0 were affected by this bug. This vulnerability affects Thunderbird < 102.7.1. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Mozilla |
Thunderbird |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| Security Vulnerabilities fixed in Thunderbird 102.7.1 — Mozilla |
MISC |
www.mozilla.org |
|
| 1769000 - (CVE-2023-0430) Message signed with revoked S/MIME certificate shown as correctly signed |
MISC |
bugzilla.mozilla.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160444 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2023-0608)
- 160445 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2023-0600)
- 160449 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2023-0606)
- 181587 Debian Security Update for thunderbird (CVE-2023-0430)
- 181592 Debian Security Update for thunderbird (DLA 3324-1)
- 181680 Debian Security Update for thunderbird (DSA 5355-1)
- 199147 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5824-1)
- 241156 Red Hat Update for thunderbird (RHSA-2023:0606)
- 241157 Red Hat Update for thunderbird (RHSA-2023:0600)
- 241159 Red Hat Update for thunderbird (RHSA-2023:0608)
- 241162 Red Hat Update for thunderbird (RHSA-2023:0605)
- 241164 Red Hat Update for thunderbird (RHSA-2023:0607)
- 241165 Red Hat Update for thunderbird (RHSA-2023:0603)
- 241643 Red Hat Update for thunderbird (RHSA-2023:0602)
- 241673 Red Hat Update for thunderbird (RHSA-2023:0601)
- 257222 CentOS Security Update for thunderbird (CESA-2023:0600)
- 377942 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2023-04)
- 753663 SUSE Enterprise Linux Security Update for MozillaThunderbird (SUSE-SU-2023:0329-1)
- 940914 AlmaLinux Security Update for thunderbird (ALSA-2023:0606)
- 940917 AlmaLinux Security Update for thunderbird (ALSA-2023:0608)
- 960490 Rocky Linux Security Update for thunderbird (RLSA-2023:0606)
- 960524 Rocky Linux Security Update for thunderbird (RLSA-2023:0608)