Security features bypass in Mozilla Thunderbird - CVE-2023-0547
Published: April 11, 2023
Mozilla Thunderbird
Mozilla
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to an error when processing revocation status of S/mime recipient certificates. OCSP revocation status of recipient certificates is not checked when sending S/Mime encrypted email, as a result revoked certificates are accepted.