Impact
A maliciously crafted mail header can trigger a one-byte read past the end of a buffer in the Thunderbird mail parser, corresponding to CWE-125 and CWE-126. This off-by-one over-read could expose adjacent memory contents, potentially leaking sensitive data stored near the buffer. The flaw does not provide a direct code execution path or denial of service, but may compromise confidentiality of header information or hidden data stored adjacent to the buffer.
Affected Systems
Mozilla’s Thunderbird email client is affected. The vulnerability is fixed in Thunderbird 155, 140.15, and 153.2, so any older installations of these releases are vulnerable.
Risk and Exploitability
The CVSS score of 7.5 classifies the flaw as High severity. Despite an EPSS score of <1% indicating a low current exploitation probability, the vulnerability could expose adjacent memory contents, potentially leaking confidential data. It is not listed in the CISA KEV catalog. The attack vector is inferred to be a malicious email sent to the client, as the flaw is triggered during header parsing. While the payload does not provide code execution or denial of service, the high severity and possible confidentiality impact make applying the available fixes a priority.
OpenCVE Enrichment
Debian DLA
Debian DSA