Impact
A maliciously crafted IMAP line triggers an out‑of‑bounds read in Thunderbird’s IMAP parser. This flaw can expose parts of the process memory to a remote attacker or cause the client to crash, leading to service denial for the user. This vulnerability falls under the CWE-125 classification.
Affected Systems
Mozilla Thunderbird for desktop; any version older than 140.16, 153.3, or 156 is susceptible.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote adversary who can control Thunderbird’s malicious IMAP server.
OpenCVE Enrichment
Debian DLA
Debian DSA