Bugzilla – Bug 1093972
VUL-0: CVE-2018-5170: MozillaThunderbird: Filename spoofing for external attachments
Last modified: 2019-05-01 14:16:40 UTC
It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-5170 https://bugzilla.mozilla.org/show_bug.cgi?id=1411732 https://www.mozilla.org/en-US/security/advisories/mfsa2018-13/#CVE-2018-5170
SLE 15 and Leap are current/fix with this. Resolving.