Unrated severityNVD Advisory· Published Jul 24, 2023· Updated Dec 18, 2025
File Extension Spoofing using the Text Direction Override Character
CVE-2023-3417
Description
Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- osv-coords8 versionspkg:rpm/almalinux/thunderbirdpkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP4pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP5
< 102.14.0-1.el8_8.alma+ 7 more
- (no CPE)range: < 102.14.0-1.el8_8.alma
- (no CPE)range: < 115.0.1-150200.8.124.1
- (no CPE)range: < 115.0.1-150200.8.124.1
- (no CPE)range: < 102.13.1-1.1
- (no CPE)range: < 115.0.1-150200.8.124.1
- (no CPE)range: < 115.0.1-150200.8.124.1
- (no CPE)range: < 115.0.1-150200.8.124.1
- (no CPE)range: < 115.0.1-150200.8.124.1
- Range: unspecified
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.