Impact
An untrusted IMAP server can send an untagged '* ID' response that triggers an out-of-bounds read in Thunderbird’s IMAP response parser before authentication has completed. The read causes the application to crash, effectively denying service to the user. This is a classic out‑of‑bounds read flaw (CWE‑125) and does not provide remote code execution or data disclosure.
Affected Systems
Mozilla Thunderbird versions earlier than 156, 140.16, and 153.3 are affected. The fix is included in Thunderbird releases 156, 140.16, and 153.3 and later.
Risk and Exploitability
The CVSS score of 3.4 indicates a low severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to act as an IMAP server to send malformed responses, so the attack vector is remote and requires no authentication on the client side, but the overall risk is low.
OpenCVE Enrichment
Debian DLA
Debian DSA