A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-of-service (DOS) attack because Thunderbird reopens the last seen message on restart, triggering the crash again. This vulnerability affects Thunderbird < 60.5.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade thunderbird | Apr 29, 2019 | Apr 26, 2019 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird.Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox. | Apr 3, 2019 | Apr 2, 2019 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 60.5 | Mar 8, 2019 | Jan 29, 2019 |
| Oracle Solaris | — | Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 60.6.1-11.4.9.0.1.2.0 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 68.6.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade mail/thunderbird to version 60.6.1-11.4.9.0.1.2.0 on Solaris 11.4Upgrade web/browser/firefox to version 68.6.0-11.4.21.0.1.69.0 on Solaris 11.4 | May 30, 2019 | Apr 26, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub