When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 128.2.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | Sep 23, 2024 | Sep 6, 2024 |
| Debian | — | Upgrade thunderbird | Jul 27, 2026 | Jul 27, 2026 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade dev-lang/spidermonkey.Upgrade mail-client/thunderbird.Upgrade www-client/firefox.Upgrade www-client/firefox-bin. | Dec 9, 2024 | Sep 6, 2024 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 128.2Upgrade to the latest version of Mozilla Thunderbird | Sep 9, 2024 | Sep 6, 2024 |
| Oracle_linux | — | Upgrade thunderbird | Oct 16, 2024 | Sep 6, 2024 |
| Redhat_linux | — | No solution existsUpgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfo | Sep 18, 2024 | Sep 6, 2024 |
| Rocky_linux | — | Upgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade thunderbird | Sep 17, 2024 | Sep 6, 2024 |
| Suse | — | Upgrade MozillaThunderbird-translations-commonUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-other | Dec 31, 2024 | Sep 6, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub