CVE-2023-29479
published 2023-04-24CVE-2023-29479: Ribose RNP before 0.16.3 may hang when the input is malformed.
PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.90%
56.0th percentile
Ribose RNP before 0.16.3 may hang when the input is malformed.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rnp | < rnp 0.16.3-1 (bookworm) | rnp 0.16.3-1 (bookworm) |
| debian | thunderbird | < rnp 0.16.3-1 (bookworm) | rnp 0.16.3-1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | >= 0 < 1:102.10.0-1~deb11u1 | 1:102.10.0-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0-1 | 1:102.10.0-1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0-1 | 1:102.10.0-1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0-1 | 1:102.10.0-1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0+build2-0ubuntu0.18.04.1 | 1:102.10.0+build2-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0+build2-0ubuntu0.20.04.1 | 1:102.10.0+build2-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0+build2-0ubuntu0.22.04.1 | 1:102.10.0+build2-0ubuntu0.22.04.1 |
| ribose | rnp | < 0.16.3 | 0.16.3 |
| ribose | rnp | >= 0 < 0.16.3-1 | 0.16.3-1 |
| ribose | rnp | >= 0 < 0.16.3-1 | 0.16.3-1 |
| ribose | rnp | >= 0 < 0.16.3-1 | 0.16.3-1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2023-04-13·CVSS 6.5
CVE-2023-29535 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-1945, CVE-2023-29548,
CVE-2023-29550)
Paul Menzel discovered that Thunderbird did not properly validate OCSP
revocation status of recipient certificates when sending S/Mime encrypted
email. An attacker could potentially exploits this issue to perform
spoofing attack. (CVE-2023-0547)
Ribose RNP Team discovered that Thunderbird did not properly manage memory
when pa
Red Hat
Thunderbird: Hang when processing certain OpenPGP messages
vendor_redhat·2023-04-11·CVSS 5.3
CVE-2023-29479 [MEDIUM] CWE-400 Thunderbird: Hang when processing certain OpenPGP messages
Thunderbird: Hang when processing certain OpenPGP messages
Ribose RNP before 0.16.3 may hang when the input is malformed.
The Mozilla Foundation Security Advisory describes this flaw as:
Certain malformed OpenPGP messages could trigger incorrect parsing of PKESK/SKESK packets due to a bug in the Ribose RNP library used by Thunderbird up to version 102.9.1, which would cause the Thunderbird user interface to hang. The issue was discovered using Google's oss-fuzz.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: thunderbird (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2023-29479: rnp - Ribose RNP before 0.16.3 may hang when the input is malformed.
vendor_debian·2023·CVSS 5.3
CVE-2023-29479 [MEDIUM] CVE-2023-29479: rnp - Ribose RNP before 0.16.3 may hang when the input is malformed.
Ribose RNP before 0.16.3 may hang when the input is malformed.
Scope: local
bookworm: resolved (fixed in 0.16.3-1)
forky: resolved (fixed in 0.16.3-1)
sid: resolved (fixed in 0.16.3-1)
trixie: resolved (fixed in 0.16.3-1)
Mozilla
Mozilla Foundation Security Advisory 2023-15: CVE-2023-29479
vendor_mozilla·CVSS 5.3
CVE-2023-29479 [MEDIUM] Mozilla Foundation Security Advisory 2023-15: CVE-2023-29479
Mozilla Foundation Security Advisory 2023-15
CVE: CVE-2023-29479
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 102.10
OSV
CVE-2023-29479: Ribose RNP before 0
osv·2023-04-24·CVSS 5.3
CVE-2023-29479 [MEDIUM] CVE-2023-29479: Ribose RNP before 0
Ribose RNP before 0.16.3 may hang when the input is malformed.
GHSA
GHSA-rr9h-qqwq-gm72: Ribose RNP before 0
ghsa_unreviewed·2023-04-24
CVE-2023-29479 [MEDIUM] CWE-400 GHSA-rr9h-qqwq-gm72: Ribose RNP before 0
Ribose RNP before 0.16.3 may hang when the input is malformed.
OSV
thunderbird vulnerabilities
osv·2023-04-13·CVSS 6.5
CVE-2023-1945 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-1945, CVE-2023-29548,
CVE-2023-29550)
Paul Menzel discovered that Thunderbird did not properly validate OCSP
revocation status of recipient certificates when sending S/Mime encrypted
email. An attacker could potentially exploits this issue to perform
spoofing attack. (CVE-2023-0547)
Ribose RNP Team discovered that Thunderbird did not properly manage memory
when parsing certain OpenPGP messages. An attacker could potentially
exploi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-24
Published