Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | Feb 11, 2025 | Feb 4, 2025 |
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Feb 26, 2025 | Feb 4, 2025 |
| Debian | — | Upgrade thunderbird | Feb 10, 2025 | Feb 4, 2025 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 135.0 | Feb 5, 2025 | Feb 4, 2025 |
| Oracle_linux | — | Upgrade thunderbird | Feb 10, 2025 | Feb 4, 2025 |
| Redhat_linux | — | Upgrade thunderbirdUpgrade thunderbird-debugsourceNo solution existsUpgrade thunderbird-debuginfo | Feb 11, 2025 | Feb 4, 2025 |
| Rocky_linux | — | Upgrade thunderbird-debugsourceUpgrade thunderbirdUpgrade thunderbird-debuginfo | Feb 14, 2025 | Feb 4, 2025 |
| Suse | — | Upgrade mozillathunderbird-translations-commonUpgrade mozillathunderbirdUpgrade mozillathunderbird-translations-other | Feb 12, 2025 | Feb 4, 2025 |
| Ubuntu | — | Upgrade thunderbird | Jul 23, 2025 | Feb 4, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub