PublicDateAtUSN: 2020-05-07 00:00:00 UTC Candidate: CVE-2020-12397 PublicDate: 2020-05-22 19:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12397 https://www.mozilla.org/en-US/security/advisories/mfsa2020-18/#CVE-2020-12397 https://ubuntu.com/security/notices/USN-4373-1 Description: By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N [4.3 MEDIUM] Patches_thunderbird: upstream_thunderbird: released (68.8.0) precise/esm_thunderbird: DNE trusty_thunderbird: ignored (out of standard support) trusty/esm_thunderbird: DNE xenial_thunderbird: released (1:68.8.0+build2-0ubuntu0.16.04.2) esm-infra/xenial_thunderbird: released (1:68.8.0+build2-0ubuntu0.16.04.2) bionic_thunderbird: released (1:68.8.0+build2-0ubuntu0.18.04.2) eoan_thunderbird: released (1:68.8.0+build2-0ubuntu0.19.10.2) focal_thunderbird: released (1:68.8.0+build2-0ubuntu0.20.04.2) devel_thunderbird: released (1:68.8.0+build2-0ubuntu1)