Impact
An off‑by‑one error in Thunderbird’s MIME header parsing code lets the program read a single byte past the end of a header buffer. This vulnerable code path is exercised when a user forwards a message and has the “view all headers” option enabled. The out‑of‑bounds read can cause a crash, resulting in service denial and exposing the application to potential denial of service attacks. The weakness is an improper buffer boundary check, classified as an out‑of‑bounds read.
Affected Systems
The vulnerability affects Mozilla Thunderbird for all platforms and versions prior to Thunderbird 153 and Thunderbird 140.13. Users who run earlier releases and enable the “view all headers” setting when forwarding messages are at risk.
Risk and Exploitability
The CVSS score is 7.5 and the EPSS score is <1%, indicating a very low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a crafted email that triggers the MIME header parser during a forwarding operation, exploiting the view‑all‑headers setting. Because the impact is a crash and there is no disclosed remote exploitation beyond the local user interface context, the risk is limited to users who operate Thunderbird with the vulnerable setting enabled.
OpenCVE Enrichment
Debian DLA
Debian DSA