CVE-2023-3417
published 2023-07-24CVE-2023-3417: Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.56%
42.7th percentile
Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | thunderbird | < thunderbird 1:102.13.1-1~deb12u1 (bookworm) | thunderbird 1:102.13.1-1~deb12u1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 102.13.1 | 102.13.1 |
| mozilla | thunderbird | >= 0 < 1:102.13.1-1~deb11u1 | 1:102.13.1-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:102.13.1-1~deb12u1 | 1:102.13.1-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:102.13.1-1 | 1:102.13.1-1 |
| mozilla | thunderbird | >= 0 < 1:102.13.1-1 | 1:102.13.1-1 |
| mozilla | thunderbird | >= 0 < 1:102.15.0+build1-0ubuntu0.20.04.1 | 1:102.15.0+build1-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.15.0+build1-0ubuntu0.22.04.1 | 1:102.15.0+build1-0ubuntu0.22.04.1 |
| mozilla | thunderbird | >= 115.0 < 115.0.1 | 115.0.1 |
| mozilla | thunderbird | >= unspecified < 115.0.1 | 115.0.1 |
| mozilla | thunderbird | >= unspecified < 102.13.1 | 102.13.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2023-09-04·CVSS 7.5
CVE-2023-4049 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Junsung Lee discovered that Thunderbird did not properly validate the text
direction override unicode character in filenames. An attacker could
potentially exploits this issue by spoofing file extension while attaching
a file in emails. (CVE-2023-3417)
Max Vlasov discovered that Thunderbird Offscreen Canvas did not properly
track cross-origin tainting. An attacker could potentially exploit this
issue to access image data from another site in violation of same-origin
policy. (CVE-2023-4045)
Alexander Guryanov discovered that Thunderbird did not properly update the
value of a global variable in WASM JIT analysis in some circumstances. An
attacker could potentially exploit this issue to cause a
Red Hat
thunderbird: File Extension Spoofing using the Text Direction Override Character
vendor_redhat·2023-07-20·CVSS 7.5
CVE-2023-3417 [HIGH] CWE-434 thunderbird: File Extension Spoofing using the Text Direction Override Character
thunderbird: File Extension Spoofing using the Text Direction Override Character
Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1.
Package: thunderbird (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2023-3417: thunderbird - Thunderbird allowed the Text Direction Override Unicode Character in filenames. ...
vendor_debian·2023·CVSS 7.5
CVE-2023-3417 [HIGH] CVE-2023-3417: thunderbird - Thunderbird allowed the Text Direction Override Unicode Character in filenames. ...
Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1.
Scope: local
bookworm: resolved (fixed in 1:102.13.1-1~deb12u1)
bullseye: resolved (fixed in 1:102.13.1-1~deb11u1)
forky: resolved (fixed in 1:102.13.1-1)
sid: resolved (fixed in 1:102.13.1-1)
trixie: resolved (fixed in 1:102.13.1-1)
Mozilla
Mozilla Foundation Security Advisory 2023-27: CVE-2023-3417
vendor_mozilla·CVSS 7.5
CVE-2023-3417 [HIGH] Mozilla Foundation Security Advisory 2023-27: CVE-2023-3417
Mozilla Foundation Security Advisory 2023-27
CVE: CVE-2023-3417
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 115.0.1
Mozilla
Mozilla Foundation Security Advisory 2023-28: CVE-2023-3417
vendor_mozilla·CVSS 7.5
CVE-2023-3417 [HIGH] Mozilla Foundation Security Advisory 2023-28: CVE-2023-3417
Mozilla Foundation Security Advisory 2023-28
CVE: CVE-2023-3417
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 102.13.1
OSV
thunderbird vulnerabilities
osv·2023-09-04·CVSS 7.5
CVE-2023-3417 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Junsung Lee discovered that Thunderbird did not properly validate the text
direction override unicode character in filenames. An attacker could
potentially exploits this issue by spoofing file extension while attaching
a file in emails. (CVE-2023-3417)
Max Vlasov discovered that Thunderbird Offscreen Canvas did not properly
track cross-origin tainting. An attacker could potentially exploit this
issue to access image data from another site in violation of same-origin
policy. (CVE-2023-4045)
Alexander Guryanov discovered that Thunderbird did not properly update the
value of a global variable in WASM JIT analysis in some circumstances. An
attacker could potentially exploit this issue to cause a denial of service.
(CVE-2023-4046)
Mark Brand discovered that Thund
OSV
CVE-2023-3417: Thunderbird allowed the Text Direction Override Unicode Character in filenames
osv·2023-07-24·CVSS 7.5
CVE-2023-3417 [HIGH] CVE-2023-3417: Thunderbird allowed the Text Direction Override Unicode Character in filenames
Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1.
GHSA
GHSA-xpxg-5vmj-vx9g: Thunderbird allowed the Text Direction Override Unicode Character in filenames
ghsa_unreviewed·2023-07-24
CVE-2023-3417 [HIGH] GHSA-xpxg-5vmj-vx9g: Thunderbird allowed the Text Direction Override Unicode Character in filenames
Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1835582https://lists.debian.org/debian-lts-announce/2023/07/msg00032.htmlhttps://www.debian.org/security/2023/dsa-5463https://www.mozilla.org/security/advisories/mfsa2023-27/https://www.mozilla.org/security/advisories/mfsa2023-28/https://bugzilla.mozilla.org/show_bug.cgi?id=1835582https://lists.debian.org/debian-lts-announce/2023/07/msg00032.htmlhttps://www.debian.org/security/2023/dsa-5463https://www.mozilla.org/security/advisories/mfsa2023-27/https://www.mozilla.org/security/advisories/mfsa2023-28/
2023-07-24
Published