CVE-2023-0616

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jun 2, 2023
Updated: Jan 10, 2025
CWE ID 400
CWE ID 770

Summary

CVE-2023-0616 is a vulnerability affecting Thunderbird versions below 102.8. Maliciously crafted MIME emails with a specific combination of OpenPGP and OpenPGP MIME data can cause Thunderbird's user interface to become unresponsive, potentially leading to a Denial of Service (DoS) attack. The email recipient would be unable to perform any actions within Thunderbird until the application is restarted. The vulnerability arises due to Thunderbird's repeated attempts to process and display the malicious message with the aforementioned MIME structure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mozilla Thunderbird

Affected Vendors

  • Mozilla