Злонамеренно созданный заголовок письма может привести к чтению одного байта за пределами буфера. Эта уязвимость была исправлена в Thunderbird 155, Thunderbird 140.15 и Thunderbird 153.2.
Показать оригинальное описание (EN)
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Характеристики атаки
Последствия
Строка CVSS v3.1
Тип уязвимости (CWE)
Уязвимые продукты 3
| Конфигурация | От (включительно) | До (исключительно) |
|---|---|---|
|
Mozilla Thunderbird
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
|
— |
140.15.0
|
|
Mozilla Thunderbird
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
|
141.0
|
153.2.0
|
|
Mozilla Thunderbird
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
|
154.0
|
155.0
|