CVE-2018-5161: Input Validation
Crafted message headers can cause a Thunderbird process to hang on receiving the message.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-5161?
CVE-2018-5161 is a vulnerability that allows crafted message headers to cause a Thunderbird process to hang on receiving the message.
Which versions of Thunderbird are affected by CVE-2018-5161?
Thunderbird ESR < 52.8 and Thunderbird < 52.8 are affected by CVE-2018-5161.
What is the severity of CVE-2018-5161?
CVE-2018-5161 has a severity level of medium (4) according to the CVSS scoring system.
How can I fix CVE-2018-5161?
To fix CVE-2018-5161, update Thunderbird to version 52.8 or higher.
Where can I find more information about CVE-2018-5161?
More information about CVE-2018-5161 can be found at the following references: [https://bugzilla.mozilla.org/show_bug.cgi?id=1411720](https://bugzilla.mozilla.org/show_bug.cgi?id=1411720), [https://www.mozilla.org/en-US/security/advisories/mfsa2018-13/](https://www.mozilla.org/en-US/security/advisories/mfsa2018-13/), [http://www.securitytracker.com/id/1040946](http://www.securitytracker.com/id/1040946).