Lucene search

K
redosRedosROS-20221229-03
HistoryDec 29, 2022 - 12:00 a.m.

ROS-20221229-03

2022-12-2900:00:00
redos.red-soft.ru
7
mozilla thunderbird
vulnerability
remote attackers
sensitive data
ipc messages

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

53.2%

A vulnerability in the Mozilla Thunderbird email client is related to the fact that a process can partially exit the
sandbox and read arbitrary files using IPC messages associated with the clipboard.
Exploitation of the vulnerability could allow an attacker acting remotely to open a given source and
read potentially sensitive data

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64thunderbird<= 102.6.0-1UNKNOWN

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

53.2%