We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1.
Reserved 2023-06-26 | Published 2023-07-24 | Updated 2024-10-25 | Assigner mozillaFile Extension Spoofing using the Text Direction Override Character
이준성 (Junsung Lee)
bugzilla.mozilla.org/show_bug.cgi?id=1835582
www.mozilla.org/security/advisories/mfsa2023-27/
www.mozilla.org/security/advisories/mfsa2023-28/
www.debian.org/security/2023/dsa-5463
lists.debian.org/debian-lts-announce/2023/07/msg00032.html
Support options