The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and Thunderbird 140.13.
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | RedHat | thunderbird-0:140.13.0-1.el10_2 | * |
| Red Hat Enterprise Linux 8 | RedHat | thunderbird-0:140.13.0-1.el8_10 | * |
| Red Hat Enterprise Linux 9 | RedHat | thunderbird-0:140.13.0-1.el9_8 | * |