Impact
The vulnerability involves ambiguous parsing of mail headers, which can cause multiple header fields to be interpreted as a single entry or trigger memory safety violations. This flaw may allow an attacker to corrupt the parsing logic, leading to incorrect handling of message headers and potentially enabling further exploitation such as data corruption, bypass of integrity checks, or exploitation of downstream components that rely on accurate header information. Mozilla Thunderbird is affected. Versions up to 156, 140.16, and 153.3 are impacted; the stated fixes are in Thunderbird 156, 140.16, and 153.3, so any earlier releases without those patches are vulnerable. The exploit probability is very low (<1% EPSS) and the vulnerability is not listed in CISA KEV, indicating a low immediate threat. Based on the description, it is inferred that the likely attack vector is delivery of a specially crafted email to a target system. An attacker might gain indirect influence over the application by manipulating header values or cause memory corruption that could lead to further compromise.
Affected Systems
Mozilla Thunderbird is affected. Versions up to 156, 140.16, and 153.3 are impacted; the stated fixes are in Thunderbird 156, 140.16, and 153.3, so any earlier releases without those patches are vulnerable.
Risk and Exploitability
The exploit probability is very low (<1% EPSS) and the vulnerability is not listed in CISA KEV, indicating a low immediate is delivery of a specially crafted email to a target system, after which ambiguous header parsing could be triggered. An attacker might gain indirect influence over the application by manipulating header values or cause memory corruption that could lead to further compromise. Monitoring for anomalous email headers and enforcing strict parsing limits are recommended until a patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA