CVE-2023-0547: Medium severity thunderbird vulnerability
Published Apr 11, 2023
·Updated
Last updated 24 July 2024
Other sources
OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird versions from 68 to 102.9.1 were affected by this bug.
Affected Software
3 affected componentsFixes available
debian/thunderbird
1:115.12.0-1~deb11u11:115.15.0-1~deb11u11:115.12.0-1~deb12u11:115.15.0-1~deb12u11:128.2.0esr-11:128.3.0esr-1
Mozilla Thunderbird<102.10
102.10
Mozilla Thunderbird>=68.0<102.10
Event History
Apr 11, 2023
CVE Published
12:00 AM
Jun 2, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
05:15 PM
Description
Jan 12, 2024
Data Sourced
via Launchpad·12:13 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:40 AM
RemedyDescriptionSeverityAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-0547.
2
Which software is affected by this vulnerability?
Thunderbird versions from 68 to 102.9.1 are affected by this vulnerability.
3
What is the severity of CVE-2023-0547?
The severity of CVE-2023-0547 is high with a severity value of 7.
4
How does CVE-2023-0547 affect Thunderbird?
CVE-2023-0547 affects Thunderbird by not checking the OCSP revocation status of recipient certificates when sending S/Mime encrypted email, allowing revoked certificates to be accepted.
5
How can I fix CVE-2023-0547?
To fix CVE-2023-0547, update Thunderbird to version 102.10 or later.