CVE Database
/

CVE-2018-5170

Back to search

CVE-2018-5170

Published: Jun 11, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

VendorProductVersions

Mozilla

Thunderbird ESR

affected
unspecified - < 52.8

Mozilla

Thunderbird

affected
unspecified - < 52.8

References

RHSA-2018:1726
vendor-advisory
x_refsource_REDHAT
GLSA-201811-13
vendor-advisory
x_refsource_GENTOO
USN-3660-1
vendor-advisory
x_refsource_UBUNTU
1040946
vdb-entry
x_refsource_SECTRACK
RHSA-2018:1725
vendor-advisory
x_refsource_REDHAT
DSA-4209
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now