跳转到帖子

Amazon Linux AMI 2: CVE-2022-2226: Security patch for thunderbird (ALAS-2022-1828)

recommended_posts

发布于
  • Members

Amazon Linux AMI 2: CVE-2022-2226: Security patch for thunderbird (ALAS-2022-1828)

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:N/I:C/A:N)
Published
12/22/2022
Created
02/22/2023
Added
02/21/2023
Modified
01/30/2025

Description

An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email's date will be shown. If the dates were different, then Thunderbird didn't report the email as having an invalid signature. If an attacker performed a replay attack, in which an old email with old contents are resent at a later time, it could lead the victim to believe that the statements in the email are current. Fixed versions of Thunderbird will require that the signature's date roughly matches the displayed date of the email. This vulnerability affects Thunderbird < 102 and Thunderbird < 91.11.

Solution(s)

  • amazon-linux-ami-2-upgrade-thunderbird
  • amazon-linux-ami-2-upgrade-thunderbird-debuginfo

References

  • https://attackerkb.com/topics/cve-2022-2226
  • AL2/ALAS-2022-1828
  • CVE - 2022-2226
  • 查看数 697
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…