PT-2026-54447 · Mozilla · Thunderbird
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Thunderbird versions prior to 140.12.1
Thunderbird versions prior to 152.0.1
Description
A malicious LDAP server can cause the Thunderbird LDAP client to crash due to memory exhaustion. This occurs when the client is configured to query the server for address-book autocomplete, allowing the server to stash arbitrarily large amounts of attacker-supplied data into the client.
Recommendations
Update to version 140.12.1.
Update to version 152.0.1.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thunderbird