When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 128.2.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | Sep 23, 2024 | Sep 6, 2024 |
| Debian | — | Upgrade thunderbird | Jul 27, 2026 | Jul 27, 2026 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade www-client/firefox.Upgrade dev-lang/spidermonkey.Upgrade mail-client/thunderbird.Upgrade mail-client/thunderbird-bin. | Dec 9, 2024 | Sep 6, 2024 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 128.2 | Sep 9, 2024 | Sep 6, 2024 |
| Oracle_linux | — | Upgrade thunderbird | Oct 16, 2024 | Sep 6, 2024 |
| Redhat_linux | — | Upgrade thunderbirdNo solution existsUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfo | Sep 18, 2024 | Sep 6, 2024 |
| Rocky_linux | — | Upgrade thunderbird-debuginfoUpgrade thunderbirdUpgrade thunderbird-debugsource | Sep 17, 2024 | Sep 6, 2024 |
| Suse | — | Upgrade mozillathunderbirdUpgrade mozillathunderbird-translations-commonUpgrade mozillathunderbird-translations-other | Dec 31, 2024 | Sep 6, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub