Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mozilla

Published: 2023-07-24T10:09:37.591Z

Updated: 2023-07-28T13:12:34.115Z

Reserved: 2023-06-26T17:25:53.967Z


Link: CVE-2023-3417

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-07-24T11:15:09.953

Modified: 2023-08-01T17:53:51.063


Link: CVE-2023-3417

JSON object: View

cve-icon Redhat Information

No data.