CVE-2019-11706: High severity thunderbird vulnerability
Published Jun 13, 2019
·Updated
A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezonegetvtimezoneproperties when processing certain email messages, resulting in a crash.
Affected Software
2 affected componentsFixes available
Mozilla Thunderbird<60.7.1
60.7.1
Mozilla Thunderbird<60.7.1
Event History
Jun 13, 2019
CVE Published
12:00 AM
Jul 23, 2019
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2019-11706?
CVE-2019-11706 has been rated as critical due to its potential to cause crashes in Thunderbird.
2
How do I fix CVE-2019-11706?
To fix CVE-2019-11706, update Thunderbird to version 60.7.1 or later.
3
What does CVE-2019-11706 affect?
CVE-2019-11706 affects versions of Mozilla Thunderbird prior to 60.7.1.
4
Can CVE-2019-11706 lead to arbitrary code execution?
CVE-2019-11706 does not directly lead to arbitrary code execution but can cause crashes that may be exploited.
5
How does CVE-2019-11706 impact email functionality in Thunderbird?
CVE-2019-11706 can disrupt email functionality by causing the application to crash when processing malicious iCal data.