Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39696
HistoryMar 12, 2023 - 3:00 p.m.

Signature Verification Bypass

2023-03-1215:00:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
thunderbird
signature verification
vulnerability
certificate
ocsp
revocation
s/mime
mail
security

EPSS

0.001

Percentile

21.9%

thunderbird is vulnerable to Signature Verification Bypass. Certificate OCSP revocation status was not checked when verifying S/Mime signatures which allows mails signed with a revoked certificate to be displayed as having a valid signature.