Related Vulnerabilities: CVE-2017-7818  

A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through the DOM, in Thunderbird < 52.4. This results in a potentially exploitable crash.

Severity Critical

Remote Yes

Type Arbitrary code execution

Description

A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through the DOM, in Thunderbird < 52.4. This results in a potentially exploitable crash.

AVG-441 thunderbird 52.3.0-2 52.4.0-1 Critical Fixed

12 Oct 2017 ASA-201710-19 AVG-441 thunderbird Critical multiple issues

https://www.mozilla.org/en-US/security/advisories/mfsa2017-23/#CVE-2017-7818
https://bugzilla.mozilla.org/show_bug.cgi?id=1363723