REDHAT-BUG-2506217: Medium severity Mozilla Thunderbird vulnerability
The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and Thunderbird 140.13.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.13
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2506217?
The severity of REDHAT-BUG-2506217 is medium, rated at 4.
How do I fix REDHAT-BUG-2506217?
To fix REDHAT-BUG-2506217, update to the latest version of Mozilla Thunderbird as provided by your software vendor.
What causes the vulnerability in REDHAT-BUG-2506217?
The vulnerability in REDHAT-BUG-2506217 is caused by an off-by-one error in the code that parses MIME headers.
What is the impact of REDHAT-BUG-2506217?
The impact of REDHAT-BUG-2506217 can lead to a potential crash of Mozilla Thunderbird when viewing all headers.
Is there a workaround for REDHAT-BUG-2506217?
A workaround for REDHAT-BUG-2506217 is to disable the setting to view all headers in Mozilla Thunderbird until the fix is applied.