CVE-2023-50761

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-50761
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-50761.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-50761
Downstream
Related
Published
2023-12-19T14:15:07Z
Modified
2025-08-09T19:01:27Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare the signature creation date with the message date and time, and displayed a valid signature despite a date or time mismatch. This could be used to give recipients the impression that a message was sent at a different date or time. This vulnerability affects Thunderbird < 115.6.

References

Affected packages