Medium severity4.3NVD Advisory· Published Jun 11, 2018· Updated Jun 17, 2026
CVE-2018-5170
CVE-2018-5170
Description
It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
23cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*range: <52.8.0
- cpe:2.3:a:mozilla:thunderbird_esr:*:*:*:*:*:*:*:*range: <52.8.0
- (no CPE)range: <52.8
- (no CPE)range: unspecified
- (no CPE)range: unspecified
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
9- www.securitytracker.com/id/1040946nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2018:1725nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2018:1726nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2018/05/msg00013.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/201811-13nvdThird Party Advisory
- usn.ubuntu.com/3660-1/nvdThird Party Advisory
- www.debian.org/security/2018/dsa-4209nvdThird Party Advisory
- www.mozilla.org/security/advisories/mfsa2018-13/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions Required
News mentions
0No linked articles in our index yet.