Improper Verification of Cryptographic Signature in Mozilla Thunderbird - CVE-2023-0430
Published: February 1, 2023
Vulnerability identifier: #VU71716
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-0430
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to application does not check certificate OCSP revocation status when verifying S/Mime signatures. A remote attacker can sign their emails with a revoked certificate and they will be displayed as having a valid signature.
Affected software
Mozilla Thunderbird
Debian Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Anolis OS
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Oracle Solaris
Slackware Linux
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
SUSE Linux Enterprise Module for Packagehub Subpackages
thunderbird (Ubuntu package)
mozilla-thunderbird
thunderbird (Red Hat package)
thunderbird
MozillaThunderbird
MozillaThunderbird-debuginfo
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other
thunderbird (Debian package)
Debian Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Anolis OS
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Oracle Solaris
Slackware Linux
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
SUSE Linux Enterprise Module for Packagehub Subpackages
thunderbird (Ubuntu package)
mozilla-thunderbird
thunderbird (Red Hat package)
thunderbird
MozillaThunderbird
MozillaThunderbird-debuginfo
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other
thunderbird (Debian package)
How to mitigate CVE-2023-0430
Install updates from vendor's website.
Mozilla Thunderbird - update to 102.7.1
thunderbird (Ubuntu package) - addressed in versions 1:102.7.1+build2-0ubuntu0.18.04.1, 1:102.7.1+build2-0ubuntu0.20.04.1, 1:102.7.1+build2-0ubuntu0.22.04.1, 1:102.7.1+build2-0ubuntu0.22.10.1
mozilla-thunderbird - update to 102.7.1
thunderbird (Red Hat package) - addressed in versions 102.7.1-2.el7_9, 102.7.1-2.el8_1, 102.7.1-2.el8_2, 102.7.1-2.el8_4, 102.7.1-2.el8_6, 102.7.1-2.el8_7, 102.7.1-2.el9_0, 102.7.1-2.el9_1
thunderbird - update to 102.7.1-2.0.1
MozillaThunderbird - update to 102.7.1-150200.8.102.1
MozillaThunderbird-debuginfo - update to 102.7.1-150200.8.102.1
MozillaThunderbird-debugsource - update to 102.7.1-150200.8.102.1
MozillaThunderbird-translations-common - update to 102.7.1-150200.8.102.1
MozillaThunderbird-translations-other - update to 102.7.1-150200.8.102.1
thunderbird (Debian package) - update to 1:102.8.0-1~deb11u1
thunderbird (Ubuntu package) - addressed in versions 1:102.7.1+build2-0ubuntu0.18.04.1, 1:102.7.1+build2-0ubuntu0.20.04.1, 1:102.7.1+build2-0ubuntu0.22.04.1, 1:102.7.1+build2-0ubuntu0.22.10.1
mozilla-thunderbird - update to 102.7.1
thunderbird (Red Hat package) - addressed in versions 102.7.1-2.el7_9, 102.7.1-2.el8_1, 102.7.1-2.el8_2, 102.7.1-2.el8_4, 102.7.1-2.el8_6, 102.7.1-2.el8_7, 102.7.1-2.el9_0, 102.7.1-2.el9_1
thunderbird - update to 102.7.1-2.0.1
MozillaThunderbird - update to 102.7.1-150200.8.102.1
MozillaThunderbird-debuginfo - update to 102.7.1-150200.8.102.1
MozillaThunderbird-debugsource - update to 102.7.1-150200.8.102.1
MozillaThunderbird-translations-common - update to 102.7.1-150200.8.102.1
MozillaThunderbird-translations-other - update to 102.7.1-150200.8.102.1
thunderbird (Debian package) - update to 1:102.8.0-1~deb11u1
External References
Related Security Bulletins
- Spoofing attack in Mozilla Thunderbird
- Slackware Linux update for mozilla-thunderbird
- Ubuntu update for thunderbird
- Red Hat Enterprise Linux 9 update for thunderbird
- Red Hat Enterprise Linux 9.0 Extended Update Support update for thunderbird
- Red Hat Enterprise Linux 8 update for thunderbird
- Red Hat Enterprise Linux 8.6 Extended Update Support update for thunderbird
- Red Hat Enterprise Linux 8.4 Extended Update Support update for thunderbird
- Red Hat Enterprise Linux 8 update for thunderbird
- Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions update for thunderbird
- Red Hat Enterprise Linux 7 update for thunderbird
- SUSE update for MozillaThunderbird
- Debian update for thunderbird
- CentOS 7 update for thunderbird
- Multiple vulnerabilities in Oracle Solaris third-party software
- Anolis OS update for thunderbird
- Anolis OS update for thunderbird