Impact
A malicious IMAP server can send a specially crafted ID response that causes Thunderbird to experience a use‑after‑free condition. This frees heap memory prematurely and allows the client to read the freed memory region. The leaked data can then be written to the user’s prefs.js configuration file, revealing sensitive information that was stored there. The root weakness is a use‑after‑free bug that leads to data disclosure.
Affected Systems
All versions of Thunderbird prior to 155, 140.15, and 153.2 are vulnerable. Updating the client to any of the patched releases removes this issue.
Risk and Exploitability
The flaw is exploitable by an attacker who can control the IMAP server to which a Thunderbird client connects. The attack path requires only a crafted server response delivered over the network. Although an EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the ability to trigger the bug remotely and potentially alter local configuration files makes the risk significant for any users that interface with untrusted IMAP servers.
OpenCVE Enrichment