#VU62808 Spoofing attack in Mozilla Thunderbird - CVE-2022-1520
Published: May 5, 2022
Mozilla Thunderbird
Mozilla
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data when processing signed and encrypted attached messages. If an email contains 2 attached messages, Thunderbird displays security status of the first opened attached message for the second attached message. As a result an attacker can spoof security status of the second attached message.