Red Hat Bugzilla – Bug 1530195
CVE-2017-7829 Mozilla: From address with encoded null character is cut off in message header display
Last modified: 2018-01-07 23:58:50 EST
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string.
Acknowledgments: Name: the Mozilla project Upstream: Sabri Haddouche
External References: https://www.mozilla.org/en-US/security/advisories/mfsa2017-30/#CVE-2017-7829
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Red Hat Enterprise Linux 6 Via RHSA-2018:0061 https://access.redhat.com/errata/RHSA-2018:0061