CVE-2023-0616

EUVD-2023-12651
If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause Thunderbird's user interface to lock up and no longer respond to the user's actions. An attacker could send a crafted message with this structure to attempt a DoS attack. This vulnerability affects Thunderbird < 102.8.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA-ADPADP
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 28%
Affected Products (NVD)
VendorProductVersion
mozillathunderbird
𝑥
< 102.8
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
thunderbird
bookworm
1:115.16.0esr-1~deb12u1
fixed
bookworm (security)
1:128.5.0esr-1~deb12u1
fixed
bullseye
1:115.12.0-1~deb11u1
fixed
bullseye (security)
1:128.5.0esr-1~deb11u1
fixed
sid
1:128.5.2esr-1
fixed
trixie
1:128.5.2esr-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
thunderbird
bionic
Fixed 1:102.8.0+build2-0ubuntu0.18.04.1
released
focal
Fixed 1:102.8.0+build2-0ubuntu0.20.04.1
released
jammy
Fixed 1:102.8.0+build2-0ubuntu0.22.04.1
released
kinetic
Fixed 1:102.8.0+build2-0ubuntu0.22.10.1
released
lunar
not-affected
trusty
ignored
xenial
ignored