First published: Tue Apr 11 2023(Updated: )
Certain malformed OpenPGP messages could trigger incorrect parsing of PKESK/SKESK packets due to a bug in the Ribose RNP library used by Thunderbird up to version 102.9.1, which would cause the Thunderbird user interface to hang. The issue was discovered using Google's oss-fuzz.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <102.10 | 102.10 |
Ribose RNP | <0.16.3 | |
debian/rnp | 0.16.3-1 0.17.1-1 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:115.15.0-1~deb11u1 1:115.12.0-1~deb12u1 1:115.15.0-1~deb12u1 1:128.2.0esr-1 1:128.3.0esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-29479 is a vulnerability in the Ribose RNP library used by Thunderbird, which could cause the Thunderbird user interface to hang when handling certain malformed OpenPGP messages.
CVE-2023-29479 affects Thunderbird versions up to 102.9.1, causing the user interface to hang when processing certain malformed OpenPGP messages.
CVE-2023-29479 has a medium severity rating.
To fix CVE-2023-29479, update Thunderbird to version 102.10 or later.
More information about CVE-2023-29479 can be found in the following references: [Link 1](https://www.rnpgp.org/blog/2023-04-13-rnp-release-0-16-3/), [Link 2](https://cve.ribose.com/advisories/ra-2023-04-11/), [Link 3](https://launchpad.net/bugs/cve/CVE-2023-29479)