QID 198755

Date Published: 2022-04-28

QID 198755: Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5393-1)

Multiple security issues were discovered in Thunderbird.
Thunderbird ignored openpgp revocation whenimporting a revoked key in some circumstances.

If a user weretricked into opening a specially crafted website in a browsing context, anattacker could potentially exploit these to cause a denial of service,conduct spoofing attacks, or execute arbitrary code.
An attacker couldpotentially exploit this by tricking the user into trusting theauthenticity of a message or tricking them into use a revoked key tosend an encrypted message.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5393-1 for updates and patch information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-5393-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5393-1