Mozilla: OpenPGP revocation information was ignored
Published Dec 22, 2022
6.1
MEDIUMCVSS 3.1
EPSS 0.38%
Description
When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was not yet revoked, and the existing key was kept as non-revoked. Revocation statements that used another revocation reason, or that didn't specify a revocation reason, were unaffected. This vulnerability affects Thunderbird < 91.8.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<91.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mozilla | Thunderbird | n/a |
|
- < 91.8
No data.
Red Hat Enterprise Linux 7
thunderbird-0:91.8.0-1.el7_9
Fixed · RHSA-2022:1302
Red Hat Enterprise Linux 8
thunderbird-0:91.8.0-1.el8_5
Fixed · RHSA-2022:1301
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
thunderbird-0:91.8.0-1.el8_1
Fixed · RHSA-2022:1303
Red Hat Enterprise Linux 8.2 Extended Update Support
thunderbird-0:91.8.0-1.el8_2
Fixed · RHSA-2022:1326
Red Hat Enterprise Linux 8.4 Extended Update Support
thunderbird-0:91.8.0-1.el8_4
Fixed · RHSA-2022:1305
Red Hat Enterprise Linux 6
thunderbird
Out of support scope
Red Hat Enterprise Linux 9
thunderbird
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | thunderbird-0:91.8.0-1.el7_9 | Fixed | RHSA-2022:1302 |
| Red Hat Enterprise Linux 8 | thunderbird-0:91.8.0-1.el8_5 | Fixed | RHSA-2022:1301 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | thunderbird-0:91.8.0-1.el8_1 | Fixed | RHSA-2022:1303 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | thunderbird-0:91.8.0-1.el8_2 | Fixed | RHSA-2022:1326 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | thunderbird-0:91.8.0-1.el8_4 | Fixed | RHSA-2022:1305 |
| Red Hat Enterprise Linux 6 | thunderbird | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | thunderbird | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-1197 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1754985 Issue TrackingPermissions RequiredVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2072963 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24537 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1197
- https://www.cve.org/CVERecord?id=CVE-2022-1197
- https://www.mozilla.org/security/advisories/mfsa2022-15/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-1197 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1754985 | Issue TrackingPermissions RequiredVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2072963 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24537 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-1197 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-1197 | ||
| https://www.mozilla.org/security/advisories/mfsa2022-15/ | Vendor Advisory |
Change history (0)
No recorded changes yet.