The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and Thunderbird 140.13.
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Thunderbird | Mozilla | * | 140.13.0 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | thunderbird-0:140.13.0-1.el10_2 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | thunderbird-0:140.13.0-1.el10_0 | * |
| Red Hat Enterprise Linux 8 | RedHat | thunderbird-0:140.13.0-1.el8_10 | * |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | thunderbird-0:140.13.0-1.el8_4 | * |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | RedHat | thunderbird-0:140.13.0-1.el8_4 | * |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | thunderbird-0:140.13.0-1.el8_6 | * |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | RedHat | thunderbird-0:140.13.0-1.el8_6 | * |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | RedHat | thunderbird-0:140.13.0-1.el8_8 | * |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | RedHat | thunderbird-0:140.13.0-1.el8_8 | * |
| Red Hat Enterprise Linux 9 | RedHat | thunderbird-0:140.13.0-1.el9_8 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | thunderbird-0:140.13.0-1.el9_2 | * |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | RedHat | thunderbird-0:140.13.0-1.el9_4 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | thunderbird-0:140.13.0-1.el9_6 | * |