First published: Tue Nov 12 2024(Updated: )
Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <132.0.1 | 132.0.1 |
Thunderbird | <128.4.3 | 128.4.3 |
Thunderbird | <128.4.3 | |
Thunderbird | >=129.0<132.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-11159 has a high severity due to its potential for plaintext disclosure.
To fix CVE-2024-11159, update Thunderbird to version 128.4.3 or later, or to version 132.0.1 or later.
Thunderbird versions prior to 128.4.3 and between 129.0 and 132.0.1 are affected by CVE-2024-11159.
CVE-2024-11159 exploits the use of remote content in OpenPGP encrypted messages.
The main consequence of CVE-2024-11159 is the potential disclosure of sensitive plaintext information.