VDB

DEBIAN-CVE-2022-1197

DEBIAN-CVE-2022-1197 PUBLISHED CVSS 5.400000095367432 MEDIUM

When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was not yet revoked, and the existing key was kept as non-revoked. Revocation statements that used another revocation reason, or that didn't specify a revocation reason, were unaffected. This vulnerability affects Thunderbird < 91.8.

Risk Scores

CVSS v3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
Debian:12thunderbird0, 0, 0
Debian:13thunderbird0, 0, 0
Debian:11thunderbird78.13.0-1, 78.13.0-1, 78.14.0-1
Debian:14thunderbird0, 0, 0

Timeline

  • Dec 22, 2022 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›