CVE-2023-0430

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jun 2, 2023
Updated: Jan 10, 2025
CWE ID 295

Summary

CVE-2023-0430 is a cybersecurity vulnerability that affected Thunderbird email clients from version 68 to 102.7.0. The issue involved a failure to check the Online Certificate Status Protocol (OCSP) revocation status when verifying S/Mime signatures. As a result, emails signed with revoked certificates were erroneously displayed as having valid signatures. This flaw could potentially enable man-in-the-middle attacks or email spoofing, posing a significant security risk to users. Thunderbird users are advised to upgrade to version 102.7.1 or later to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mozilla Thunderbird

Affected Vendors

  • Mozilla