Vulnerability Name:

CVE-2017-7829 (CCN-137629)

Assigned:2012-12-22
Published:2012-12-22
Updated:2018-08-07
Summary:It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This vulnerability affects Thunderbird < 52.5.2.
CVSS v3 Severity:5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
5.3 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
4.6 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-20
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2017-7829

Source: BID
Type: Third Party Advisory, VDB Entry
102258

Source: CCN
Type: BID-102258
Mozilla Thunderbird Prior to 52.5.2 Multiple Security Vulnerabilities

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1040123

Source: REDHAT
Type: Third Party Advisory
RHSA-2018:0061

Source: CONFIRM
Type: Exploit, Issue Tracking, Patch
https://bugzilla.mozilla.org/show_bug.cgi?id=1423432

Source: XF
Type: UNKNOWN
mozilla-thunderbird-cve20177829-spoofing(137629)

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20171227 [SECURITY] [DLA 1223-1] thunderbird security update

Source: UBUNTU
Type: Third Party Advisory
USN-3529-1

Source: DEBIAN
Type: Third Party Advisory
DSA-4075

Source: CCN
Type: Mozilla Foundation Security Advisory 2017-30
Security vulnerabilities fixed in Thunderbird 52.5.2

Source: CONFIRM
Type: Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2017-30/

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mozilla:thunderbird:*:*:*:*:*:*:*:* (Version < 52.5.2)

  • Configuration 2:
  • cpe:/o:redhat:enterprise_linux_aus:7.4:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_eus:7.4:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_eus:7.5:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:6::client:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*

  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*

  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*

  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:mozilla:thunderbird:52.5.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:645
    P
    Security update for php7 (Moderate) (in QA)
    2022-10-04
    oval:org.opensuse.security:def:20177829
    V
    CVE-2017-7829
    2022-09-02
    oval:org.opensuse.security:def:3546
    P
    libICE6-1.0.8-12.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:95176
    P
    MozillaThunderbird-91.8.0-150200.8.65.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:1693
    P
    Security update for stunnel (Important)
    2022-03-16
    oval:org.opensuse.security:def:64678
    P
    Security update for apache2 (Important)
    2022-01-17
    oval:org.opensuse.security:def:111905
    P
    MozillaThunderbird-91.1.1-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:1137
    P
    Security update for the Linux Kernel (Important)
    2021-11-16
    oval:org.opensuse.security:def:105478
    P
    MozillaThunderbird-91.1.1-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:66933
    P
    Security update for gd (Moderate)
    2021-09-27
    oval:org.opensuse.security:def:71352
    P
    openssh-7.9p1-4.7 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:64765
    P
    Security update for ghostscript (Critical)
    2021-09-15
    oval:org.opensuse.security:def:70289
    P
    Security update for libesmtp (Important)
    2021-09-03
    oval:org.opensuse.security:def:47987
    P
    cyrus-sasl-2.1.26-8.7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47634
    P
    gstreamer-plugins-base-1.8.3-12.11 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47794
    P
    libtasn1-4.9-3.5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47620
    P
    git-core-2.12.3-27.14.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48320
    P
    sysvinit-tools-2.88+-101.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47673
    P
    libXdmcp6-1.1.1-12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48172
    P
    libpng12-0-1.2.50-19.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47659
    P
    krb5-appl-clients-1.0.3-1.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48080
    P
    libXinerama1-1.1.3-3.54 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47619
    P
    giflib-progs-5.0.5-12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48211
    P
    libunwind-1.1-11.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47948
    P
    apache-commons-httpclient-3.1-4.364 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48119
    P
    libgraphite2-3-1.3.1-10.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47755
    P
    libopenssl1_1-1.1.1-1.9 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47658
    P
    krb5-1.12.5-40.28.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:1098
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101020
    P
    minicom-2.7.1-1.19 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1732
    P
    open-vm-tools-desktop-11.2.5-1.17 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1773
    P
    Security update for MozillaThunderbird (Important)
    2021-07-22
    oval:org.opensuse.security:def:68012
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 15 SP1) (Important)
    2021-07-14
    oval:org.opensuse.security:def:66841
    P
    Security update for freeradius-server (Moderate)
    2021-06-23
    oval:org.opensuse.security:def:48847
    P
    lhasa-0.2.0-5.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:63524
    P
    MozillaThunderbird-52.8-1.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48534
    P
    libpng12-0-1.2.50-13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48776
    P
    gnome-shell-calendar-3.20.4-70.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:2435
    P
    MozillaThunderbird-52.8-1.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48657
    P
    yast2-3.1.206-36.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48886
    P
    telepathy-gabble-0.18.3-5.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48745
    P
    libsilc-1_1-2-1.1.10-24.128 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48573
    P
    libzip2-0.11.1-12.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48815
    P
    raptor-2.0.10-3.67 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48680
    P
    libIlmImf-Imf_2_1-21-32bit-2.1.0-4.5 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48359
    P
    DirectFB-1.7.1-6.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48784
    P
    libFLAC++6-32bit-1.3.0-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48719
    P
    freerdp-1.0.2-7.9 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48618
    P
    rsyslog-8.4.0-14.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:73624
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:68112
    P
    Security update for the Linux Kernel (Live Patch 14 for SLE 15 SP1) (Important)
    2021-03-17
    oval:org.opensuse.security:def:94307
    P
    MozillaThunderbird-68.8.0-3.80.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71465
    P
    cups-filters-1.25.0-1.107 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63563
    P
    MozillaThunderbird-60.6.1-3.28.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2474
    P
    MozillaThunderbird-60.6.1-3.28.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117201
    P
    MozillaThunderbird-68.8.0-3.80.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63604
    P
    MozillaThunderbird-68.8.0-3.80.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103747
    P
    MozillaThunderbird-60.6.1-3.28.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2515
    P
    MozillaThunderbird-68.8.0-3.80.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:90092
    P
    MozillaThunderbird-60.6.1-3.28.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107686
    P
    MozillaThunderbird-68.8.0-3.80.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:25627
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:50134
    P
    MozillaThunderbird on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25252
    P
    Security update for ipmitool (Important)
    2020-12-01
    oval:org.opensuse.security:def:26323
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25195
    P
    Security update for audiofile (Low)
    2020-12-01
    oval:org.opensuse.security:def:50080
    P
    libvirt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50173
    P
    MozillaThunderbird on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25114
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:50119
    P
    apache2-mod_php7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24987
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:25539
    P
    Security update for dbus-1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:50214
    P
    MozillaThunderbird on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24923
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25685
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24912
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25486
    P
    Security update for openssl-1_1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26358
    P
    Security update for Mozilla Thunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:50160
    P
    libpskc-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73506
    P
    jcl-over-slf4j on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25641
    P
    Security update for bcm43xx-firmware (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25336
    P
    Security update for gcc10 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70184
    P
    osc on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.artful:def:20177829000
    V
    CVE-2017-7829 on Ubuntu 17.10 (artful) - low.
    2018-06-11
    oval:com.ubuntu.xenial:def:201778290000000
    V
    CVE-2017-7829 on Ubuntu 16.04 LTS (xenial) - low.
    2018-06-11
    oval:com.ubuntu.trusty:def:20177829000
    V
    CVE-2017-7829 on Ubuntu 14.04 LTS (trusty) - low.
    2018-06-11
    oval:com.ubuntu.xenial:def:20177829000
    V
    CVE-2017-7829 on Ubuntu 16.04 LTS (xenial) - low.
    2018-06-11
    oval:com.redhat.rhsa:def:20180061
    P
    RHSA-2018:0061: thunderbird security update (Important)
    2018-01-08
    BACK
    mozilla thunderbird *
    redhat enterprise linux aus 7.4
    redhat enterprise linux desktop 6.0
    redhat enterprise linux desktop 7.0
    redhat enterprise linux eus 7.4
    redhat enterprise linux eus 7.5
    redhat enterprise linux server 6.0
    redhat enterprise linux server 7.0
    redhat enterprise linux workstation 6.0
    redhat enterprise linux workstation 7.0
    debian debian linux 7.0
    debian debian linux 8.0
    debian debian linux 9.0
    canonical ubuntu linux 14.04
    canonical ubuntu linux 16.04
    canonical ubuntu linux 17.10
    mozilla thunderbird 52.5.1