CVE-2023-50761: Medium severity thunderbird vulnerability
Last updated 24 July 2024
Other sources
The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare the signature creation date with the message date and time, and displayed a valid signature despite a date or time mismatch. This could be used to give recipients the impression that a message was sent at a different date or time.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-50761?
CVE-2023-50761 is classified as a moderate severity vulnerability.
How do I fix CVE-2023-50761?
To fix CVE-2023-50761, update Thunderbird or Firefox to versions higher than 115.6 or apply available security patches.
What products are affected by CVE-2023-50761?
CVE-2023-50761 affects Mozilla Thunderbird and Red Hat's Firefox when running versions up to and including 115.6.
What impact does CVE-2023-50761 have on users?
CVE-2023-50761 can lead to the incorrect display of valid digital signatures on emails, potentially misleading users.
Is there a workaround for CVE-2023-50761?
Currently, there are no recommended workarounds for CVE-2023-50761; the best solution is to upgrade to secure versions.