#VU64769 Improper Verification of Cryptographic Signature in Mozilla Thunderbird - CVE-2022-2226
Published: June 29, 2022
Mozilla Thunderbird
Mozilla
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to improper validation of digital signatures. When displaying an email that contains a digital signature, the email's
date will be shown. If the dates were different, then Thunderbird didn't
report the email as having an invalid signature. If an attacker
performed a replay attack, in which an old email with old contents are
resent at a later time, it could lead the victim to believe that the
statements in the email are current.