CVE-2023-50762: Medium severity thunderbird vulnerability
Last updated 24 July 2024
Other sources
When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text was interpreted as a MIME message and the first paragraph was always treated as an email header section. A digitally signed text from a different context, such as a signed GIT commit, could be used to spoof an email message.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-50762?
CVE-2023-50762 is categorized as a moderate severity vulnerability.
How do I fix CVE-2023-50762?
To fix CVE-2023-50762, update Thunderbird or Firefox to version 115.6 or later.
What systems are affected by CVE-2023-50762?
CVE-2023-50762 affects Mozilla Thunderbird and Firefox versions up to 115.6.
What type of vulnerability is CVE-2023-50762?
CVE-2023-50762 is a code execution vulnerability associated with PGP/MIME payload processing.
Are there any workarounds for CVE-2023-50762 before applying a patch?
There are no specific workarounds available for CVE-2023-50762; upgrading is recommended.