CVE-2019-11703: Buffer Overflow
Published Jun 13, 2019
·Updated
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parsergetnextchar when processing certain email messages, resulting in a potentially exploitable crash.
Affected Software
2 affected componentsFixes available
Mozilla Thunderbird<60.7.1
60.7.1
Mozilla Thunderbird<60.7.1
Event History
Jun 13, 2019
CVE Published
12:00 AM
Jul 23, 2019
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2019-11703?
CVE-2019-11703 has been classified as a high severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2019-11703?
To fix CVE-2019-11703, update your Mozilla Thunderbird to version 60.7.1 or later.
3
Which versions of Thunderbird are affected by CVE-2019-11703?
CVE-2019-11703 affects all versions of Mozilla Thunderbird prior to 60.7.1.
4
What type of vulnerability is CVE-2019-11703?
CVE-2019-11703 is a heap buffer overflow vulnerability found in Thunderbird's iCal email message processing.
5
Can CVE-2019-11703 be exploited remotely?
Yes, CVE-2019-11703 can potentially be exploited remotely through specially crafted email messages.