Impact
A maliciously crafted IMAP line triggers an out‑of‑bounds read in Thunderbird’s IMAP parser. This flaw can expose parts of the process memory to a remote attacker or cause the client to crash, leading to service denial for the user. which falls under the CWE-811 classification Thunderbird installations running any version older than 140.16, 153.3, or 156 are susceptible.
Affected Systems
Mozilla Thunderbird for desktop; any version older than 140.16, 153.3, and 156 is susceptible.
Risk and Exploitability
Although the CVSS score is not publicly disclosed, the EPSS score of less than 1% suggests a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote adversary who can control Thunderbird malicious IMAP server.
OpenCVE Enrichment
Debian DLA
Debian DSA