If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause Thunderbird's user interface to lock up and no longer respond to the user's actions. An attacker could send a crafted message with this structure to attempt a DoS attack. This vulnerability affects Thunderbird < 102.8.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3324-1 | thunderbird security update |
Debian DSA |
DSA-5355-1 | thunderbird security update |
EUVD |
EUVD-2023-12651 | If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause Thunderbird's user interface to lock up and no longer respond to the user's actions. An attacker could send a crafted message with this structure to attempt a DoS attack. This vulnerability affects Thunderbird < 102.8. |
Ubuntu USN |
USN-5943-1 | Thunderbird vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 10 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2025-01-10T18:18:47.772Z
Reserved: 2023-02-01T00:00:00
Link: CVE-2023-0616
Updated: 2024-08-02T05:17:49.978Z
Status : Modified
Published: 2023-06-02T17:15:10.383
Modified: 2025-01-10T19:15:31.767
Link: CVE-2023-0616
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN