High severity7.5NVD Advisory· Published Jul 24, 2023· Updated Jun 17, 2026
CVE-2023-3417
CVE-2023-3417
Description
Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*range: <102.13.1
- (no CPE)range: <115.0.1, <102.13.1
- (no CPE)range: unspecified
- osv-coords8 versionspkg:rpm/almalinux/thunderbirdpkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP4pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP5
< 102.14.0-1.el8_8.alma+ 7 more
- (no CPE)range: < 102.14.0-1.el8_8.alma
- (no CPE)range: < 115.0.1-150200.8.124.1
- (no CPE)range: < 115.0.1-150200.8.124.1
- (no CPE)range: < 102.13.1-1.1
- (no CPE)range: < 115.0.1-150200.8.124.1
- (no CPE)range: < 115.0.1-150200.8.124.1
- (no CPE)range: < 115.0.1-150200.8.124.1
- (no CPE)range: < 115.0.1-150200.8.124.1
Patches
Vulnerability mechanics
References
5- lists.debian.org/debian-lts-announce/2023/07/msg00032.htmlnvdMailing ListThird Party Advisory
- www.debian.org/security/2023/dsa-5463nvdThird Party Advisory
- www.mozilla.org/security/advisories/mfsa2023-27/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2023-28/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdPermissions Required
News mentions
0No linked articles in our index yet.