CVE-2023-3417
Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Linuxmint, Red Hat, Red Os, Rocky Linux
- Mozilla Thunderbird
- < 102.13.1, 115.0.1
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.7% (48th percentile)
- NVD status
- Modified
- Published
- 2023-07-24
CVE-2023-3417 at NVD
No indexed exploits for CVE-2023-3417 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-3417 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.