When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 128.2.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | Sep 23, 2024 | Sep 6, 2024 |
| Debian | — | Upgrade thunderbird | Jul 27, 2026 | Jul 27, 2026 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird-bin.Upgrade dev-lang/spidermonkey.Upgrade mail-client/thunderbird.Upgrade www-client/firefox. | Dec 9, 2024 | Sep 6, 2024 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 128.2 | Sep 9, 2024 | Sep 6, 2024 |
| Oracle_linux | — | Upgrade thunderbird | Oct 16, 2024 | Sep 6, 2024 |
| Redhat_linux | — | Upgrade thunderbirdNo solution existsUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfo | Sep 18, 2024 | Sep 6, 2024 |
| Rocky_linux | — | Upgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceUpgrade thunderbird | Sep 17, 2024 | Sep 6, 2024 |
| Suse | — | Upgrade mozillathunderbirdUpgrade mozillathunderbird-translations-commonUpgrade mozillathunderbird-translations-other | Dec 31, 2024 | Sep 6, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub