Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0566

Опубликовано: 17 фев. 2022
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write of one byte when processing the message. This vulnerability affects Thunderbird < 91.6.1.

A flaw was found in Thunderbird. The vulnerability occurs due to an out-of-bounds write of one byte when processing the message. This flaw allows an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6thunderbirdOut of support scope
Red Hat Enterprise Linux 8thunderbird:flatpak/thunderbirdAffected
Red Hat Enterprise Linux 9thunderbirdNot affected
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2022:085014.03.2022
Red Hat Enterprise Linux 8thunderbirdFixedRHSA-2022:084514.03.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsthunderbirdFixedRHSA-2022:084714.03.2022
Red Hat Enterprise Linux 8.2 Extended Update SupportthunderbirdFixedRHSA-2022:084314.03.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportthunderbirdFixedRHSA-2022:085314.03.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2055591thunderbird: Crafted email could trigger an out-of-bounds write

EPSS

Процентиль: 37%
0.00154
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 2 лет назад

It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write of one byte when processing the message. This vulnerability affects Thunderbird < 91.6.1.

CVSS3: 8.8
nvd
больше 2 лет назад

It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write of one byte when processing the message. This vulnerability affects Thunderbird < 91.6.1.

CVSS3: 8.8
debian
больше 2 лет назад

It may be possible for an attacker to craft an email message that caus ...

CVSS3: 8.8
github
больше 2 лет назад

It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write of one byte when processing the message. This vulnerability affects Thunderbird < 91.6.1.

CVSS3: 8.8
fstec
больше 3 лет назад

Уязвимость почтового клиента Mozilla Thunderbird, связанная с записью за границами буфера, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 37%
0.00154
Низкий

7.6 High

CVSS3