摘要:
Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as having a valid signature. Thunderbird versions from 68 to 102.7.0 were affected by this bug. This vulnerability affects Thunderbird < 102.7.1.
安全等级: Low
公告ID: KylinSec-SA-2025-2341
发布日期: 2025年4月20日
关联CVE: CVE-2023-0430
在验证 S/MIME 签名时,未检查证书的 OCSP 吊销状态。使用已吊销证书签名的邮件仍会被显示为具有有效签名。Thunderbird 68 至 102.7.0 版本均受此漏洞影响。该漏洞影响 Thunderbird < 102.7.1 的所有版本。
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2023-0430 | KY3.4-5A | thunderbird | Unaffected |
CVE-2023-0430 | V6 | thunderbird | Unaffected |