When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encryption or signature status. After opening and viewing the attached message B, when returning to the display of message A, the message A might be shown with the security status of message B. This vulnerability affects Thunderbird < 91.9.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3020-1 | thunderbird security update |
Debian DSA |
DSA-5141-1 | thunderbird security update |
EUVD |
EUVD-2022-24818 | When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encryption or signature status. After opening and viewing the attached message B, when returning to the display of message A, the message A might be shown with the security status of message B. This vulnerability affects Thunderbird < 91.9. |
Ubuntu USN |
USN-5435-1 | Thunderbird vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-346 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2025-04-16T15:20:58.943Z
Reserved: 2022-04-28T00:00:00.000Z
Link: CVE-2022-1520
Updated: 2024-08-03T00:10:02.838Z
Status : Modified
Published: 2022-12-22T20:15:13.217
Modified: 2025-04-16T16:15:20.437
Link: CVE-2022-1520
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN