cbcvebase.
CVE-2024-11159
published 2024-11-13

CVE-2024-11159: Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird <…

medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < 132.0.1.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianthunderbird< thunderbird 1:128.4.3esr-1~deb12u1 (bookworm)thunderbird 1:128.4.3esr-1~deb12u1 (bookworm)
mozillafirefox
mozillathunderbird< 128.4.3128.4.3
mozillathunderbird>= 0 < 1:128.4.3esr-1~deb11u11:128.4.3esr-1~deb11u1
mozillathunderbird>= 0 < 1:128.4.3esr-1~deb12u11:128.4.3esr-1~deb12u1
mozillathunderbird>= 0 < 1:128.4.3esr-11:128.4.3esr-1
mozillathunderbird>= 0 < 1:128.4.3esr-11:128.4.3esr-1
mozillathunderbird>= 129.0 < 132.0.1132.0.1
mozillathunderbird>= unspecified < 128.4.3128.4.3
mozillathunderbird>= unspecified < 132.0.1132.0.1

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
osv4.3MEDIUM