Improper Verification of Cryptographic Signature in Mozilla Thunderbird - CVE-2023-0430

 

Improper Verification of Cryptographic Signature in Mozilla Thunderbird - CVE-2023-0430

Published: February 1, 2023


Vulnerability identifier: #VU71716
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-0430
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to application does not check certificate OCSP revocation status when verifying S/Mime signatures. A remote attacker can sign their emails with a revoked certificate and they will be displayed as having a valid signature.


Affected software

Mozilla Thunderbird
Debian Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Anolis OS
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Oracle Solaris
Slackware Linux
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
SUSE Linux Enterprise Module for Packagehub Subpackages
thunderbird (Ubuntu package)
mozilla-thunderbird
thunderbird (Red Hat package)
thunderbird
MozillaThunderbird
MozillaThunderbird-debuginfo
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other
thunderbird (Debian package)

How to mitigate CVE-2023-0430

Install updates from vendor's website.

Mozilla Thunderbird - update to 102.7.1
thunderbird (Ubuntu package) - addressed in versions 1:102.7.1+build2-0ubuntu0.18.04.1, 1:102.7.1+build2-0ubuntu0.20.04.1, 1:102.7.1+build2-0ubuntu0.22.04.1, 1:102.7.1+build2-0ubuntu0.22.10.1
mozilla-thunderbird - update to 102.7.1
thunderbird (Red Hat package) - addressed in versions 102.7.1-2.el7_9, 102.7.1-2.el8_1, 102.7.1-2.el8_2, 102.7.1-2.el8_4, 102.7.1-2.el8_6, 102.7.1-2.el8_7, 102.7.1-2.el9_0, 102.7.1-2.el9_1
thunderbird - update to 102.7.1-2.0.1
MozillaThunderbird - update to 102.7.1-150200.8.102.1
MozillaThunderbird-debuginfo - update to 102.7.1-150200.8.102.1
MozillaThunderbird-debugsource - update to 102.7.1-150200.8.102.1
MozillaThunderbird-translations-common - update to 102.7.1-150200.8.102.1
MozillaThunderbird-translations-other - update to 102.7.1-150200.8.102.1
thunderbird (Debian package) - update to 1:102.8.0-1~deb11u1

External References

Related Security Bulletins