QID 379061

Date Published: 2023-11-27

QID 379061: Mozilla Thunderbird Multiple Vulnerabilities (MFSA2023-52)

Thunderbird is a free and open-source cross-platform email client developed for Windows, OS X, and Linux, with a mobile version for Android.

Mozilla Thunderbird is prone to
CVE-2023-6204: Out-of-bound memory access in WebGL2 blitFramebuffer
CVE-2023-6205: Use-after-free in MessagePort::Entangled
CVE-2023-6206: Clickjacking permission prompts using the fullscreen transition
CVE-2023-6207: Use-after-free in ReadableByteStreamQueueEntry::Buffer
CVE-2023-6208: Using Selection API would copy contents into X11 primary selection.
CVE-2023-6209: Incorrect parsing of relative URLs starting with "///"
CVE-2023-6212: Memory safety bugs fixed in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5
Affected Products:
Prior to Mozilla Thunderbird 115.5

QID Detection Logic (Authenticated) :
This checks for vulnerable version of Thunderbird.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Vendor has released fix to address these vulnerabilities. Upgrade to Thunderbird 115.5 to fix vulnerability, you can also refer MFSA2023-52 or later for more details.
    Software Advisories
    Advisory ID Software Component Link
    MFSA2023-52 URL Logo www.mozilla.org/en-US/security/advisories/mfsa2023-52/