If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause Thunderbird's user interface to lock up and no longer respond to the user's actions. An attacker could send a crafted message with this structure to attempt a DoS attack. This vulnerability affects Thunderbird < 102.8.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | Feb 22, 2023 | Feb 20, 2023 |
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Feb 21, 2024 | Jun 2, 2023 |
| Centos_linux | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Feb 22, 2023 | Feb 20, 2023 |
| Debian | — | Upgrade thunderbird | Feb 21, 2023 | Feb 21, 2023 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade mail-client/thunderbird. | May 31, 2023 | May 30, 2023 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 102.8 | Feb 17, 2023 | Feb 15, 2023 |
| Oracle_linux | — | Upgrade thunderbird | Feb 21, 2023 | Feb 14, 2023 |
| Redhat_linux | — | Upgrade thunderbird-debugsourceUpgrade thunderbirdNo solution existsUpgrade thunderbird-debuginfo | Feb 22, 2023 | Feb 20, 2023 |
| Rocky_linux | — | Upgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfo | Mar 12, 2024 | Jun 2, 2023 |
| Suse | — | Upgrade mozillathunderbird-translations-commonUpgrade mozillathunderbirdUpgrade mozillathunderbird-translations-other | Mar 3, 2023 | Mar 2, 2023 |
| Ubuntu | — | Upgrade thunderbird | Mar 22, 2023 | Mar 13, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub