NA

CVE-2023-3417

Published: 24/07/2023 Updated: 01/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla thunderbird

debian debian linux 10.0

debian debian linux 11.0

debian debian linux 12.0

Vendor Advisories

A security issue was discovered in Thunderbird, which could result in spoofing of filenames of email attachments For the oldstable distribution (bullseye), this problem has been fixed in version 1:102131-1~deb11u1 For the stable distribution (bookworm), this problem has been fixed in version 1:102131-1~deb12u1 We recommend that you upgrade y ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for thunderbird is now available for Red Hat Enterprise Linux 84 Advanced Mission Critical Update Support, Red Hat ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for thunderbird is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as h ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for thunderbird is now available for Red Hat Enterprise Linux 82 Advanced Update Support, Red Hat Enterprise Linux ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for thunderbird is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as h ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for thunderbird is now available for Red Hat Enterprise Linux 90 Extended Update SupportRed Hat Product Security ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for thunderbird is now available for Red Hat Enterprise Linux 81 Update Services for SAP SolutionsRed Hat Product ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for thunderbird is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as h ...
Thunderbird allowed the Text Direction Override Unicode Character in filenames An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file Newer versions of Thunderbird will strip the character and show the correct file extension This vulnerability affects Thunderbird &lt; 11501 (CVE-2023- ...
DescriptionThe MITRE CVE dictionary describes this issue as: Thunderbird allowed the Text Direction Override Unicode Character in filenames An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file Newer versions of Thunderbird will strip the character and show the correct file extension Thi ...
Mozilla Foundation Security Advisory 2023-27 Security Vulnerabilities fixed in Thunderbird 11501 Announced July 20, 2023 Impact high Products Thunderbird Fixed in Thunderbird 11501 ...
Mozilla Foundation Security Advisory 2023-28 Security Vulnerabilities fixed in Thunderbird 102131 Announced July 4, 2023 Impact high Products Thunderbird Fixed in Thunderbird 102131 ...