CyberRota Analysis
AI-GeneratedAn out-of-bounds read vulnerability exists in the IMAP response parser of Thunderbird, which can be exploited by a malicious or compromised IMAP server sending an untagged '* ID' response, leading to a crash of the application. This issue is accessible prior to user authentication, making it particularly concerning for environments using Thunderbird for email management. Organizations using affected versions of Thunderbird should prioritize updating to versions 156 or 140.16 to mitigate potential disruptions.
Original NVD Description
A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Related CVEs
Other vulnerabilities affecting the same vendor(s)