Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | Feb 11, 2025 | Feb 4, 2025 |
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Feb 26, 2025 | Feb 4, 2025 |
| Debian | — | Upgrade thunderbird | Feb 10, 2025 | Feb 4, 2025 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 135.0 | Feb 5, 2025 | Feb 4, 2025 |
| Oracle_linux | — | Upgrade thunderbird | Feb 10, 2025 | Feb 4, 2025 |
| Redhat_linux | — | Upgrade thunderbird-debugsourceNo solution existsUpgrade thunderbird-debuginfoUpgrade thunderbird | Feb 11, 2025 | Feb 4, 2025 |
| Rocky_linux | — | Upgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade thunderbird | Feb 14, 2025 | Feb 4, 2025 |
| Suse | — | Upgrade mozillathunderbirdUpgrade mozillathunderbird-translations-commonUpgrade mozillathunderbird-translations-other | Feb 12, 2025 | Feb 4, 2025 |
| Ubuntu | — | Upgrade thunderbird | Jul 23, 2025 | Feb 4, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub