CVE-2019-11704: Buffer Overflow
Published Jun 13, 2019
·Updated
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemorystrdupanddequote when processing certain email messages, resulting in a potentially exploitable crash.
Affected Software
2 affected componentsFixes available
Mozilla Thunderbird<60.7.1
60.7.1
Mozilla Thunderbird<60.7.1
Event History
Jun 13, 2019
CVE Published
12:00 AM
Jul 23, 2019
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2019-11704?
CVE-2019-11704 is considered a medium-severity vulnerability due to its potential for causing crashes and exploitation.
2
How do I fix CVE-2019-11704?
To fix CVE-2019-11704, update Mozilla Thunderbird to version 60.7.1 or later.
3
What causes the CVE-2019-11704 vulnerability?
CVE-2019-11704 is caused by a heap buffer overflow in Thunderbird's implementation of iCal.
4
What versions of Thunderbird are affected by CVE-2019-11704?
CVE-2019-11704 affects all versions of Mozilla Thunderbird prior to 60.7.1.
5
Can CVE-2019-11704 lead to code execution?
Although CVE-2019-11704 may result in a crash, it does not directly lead to arbitrary code execution.