USN-6333-1

    Dashboard / Vulnerabilities / USN-6333-1

    USN-6333-1

    Published: 4 Sept 2023Last Modified: 22 Apr 2026

    Summary: thunderbird vulnerabilities

    Details: Junsung Lee discovered that Thunderbird did not properly validate the text direction override unicode character in filenames. An attacker could potentially exploits this issue by spoofing file extension while attaching a file in emails. (CVE-2023-3417) Max Vlasov discovered that Thunderbird Offscreen Canvas did not properly track cross-origin tainting. An attacker could potentially exploit this issue to access image data from another site in violation of same-origin policy. (CVE-2023-4045) Alexander Guryanov discovered that Thunderbird did not properly update the value of a global variable in WASM JIT analysis in some circumstances. An attacker could potentially exploit this issue to cause a denial of service. (CVE-2023-4046) Mark Brand discovered that Thunderbird did not properly validate the size of an untrusted input stream. An attacker could potentially exploit this issue to cause a denial of service. (CVE-2023-4050) Multiple security issues were discovered in Thunderbird. If a user were tricked into opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, bypass security restrictions, cross-site tracing, or execute arbitrary code. (CVE-2023-4047, CVE-2023-4048, CVE-2023-4049, CVE-2023-4055, CVE-2023-4056)

    Affected packages

    Package

    Name: thunderbird

    Purl: pkg:deb/ubuntu/thunderbird@1:102.15.0+build1-0ubuntu0.20.04.1?arch=source&distro=focal

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1:102.15.0+build1-0ubuntu0.20.04.1

    Affected versions

    1:68.1.2+build1-0ubuntu1
    1:68.1.2+build1-0ubuntu2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    USN-6333-1 | CVE-DB