[MFSA-2023-27] Security Vulnerabilities fixed in Thunderbird 115.0.1

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 2
  • CVE-2023-3417: File Extension Spoofing using the Text Direction Override Character (moderate)
    Thunderbird allowed the Text Direction Override Unicode Character in filenames.
    An email attachment could be incorrectly shown as being a document file, while in
    fact it was an executable file. Newer versions of Thunderbird will strip the character
    and show the correct file extension.

  • CVE-2023-3600: Use-after-free in workers (high)
    During the worker lifecycle, a use-after-free condition could have occured, which could have led to a potentially exploitable crash.

Package Affected Version
pkg:mozilla/Thunderbird < 115.0.1
Package Fixed Version
pkg:mozilla/Thunderbird = 115.0.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:mozilla/Thunderbird Thunderbird < 115.0.1
Fixed pkg:mozilla/Thunderbird Thunderbird = 115.0.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...