ID:6129 - Exploit for Type Confusion in Mozilla Thunderbird - CVE-2019-11706
Published: June 17, 2021
Mozilla Thunderbird
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to perform denial of service (DoS) attack.
The vulnerability exists due to a type confusion error within the iCal implementation in icaltimezone_get_vtimezone_properties function in icalproperty.c. A remote attacker can create a specially crafted email with malformed timezone data, trigger a type confusion error and crash the application.