Impact
The vulnerability involves ambiguous parsing of mail headers, which can cause multiple header fields to be interpreted as a single entry or trigger memory safety violations. This flaw may allow an attacker to corrupt the parsing logic, leading to incorrect handling of message headers and potentially enabling further exploitation such as data corruption, bypass of integrity checks, or exploitation of downstream components that rely on accurate header information.
Affected Systems
Mozilla Thunderbird is affected. Versions up to 156, 140.16, and 153.3 are impacted; the stated fixes are in Thunderbird 156, 140.16, and 153.3, so any earlier releases without those patches are vulnerable.
Risk and Exploitability
The exploit probability is very low (<1% EPSS) and the vulnerability is not listed in CISA KEV, but its CVSS score of 9.8 indicates a high severity risk. Based on the description, it is inferred that the likely attack vector is delivery of a specially crafted email to a target system. An attacker might gain indirect influence over the application by manipulating header values or cause memory corruption that could lead to further compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA