#VU18800 Type Confusion in Mozilla Thunderbird - CVE-2019-11706
Published: June 14, 2019 / Updated: June 17, 2021
Mozilla Thunderbird
Mozilla
Description
The vulnerability allows a remote attacker to perform denial of service (DoS) attack.
The vulnerability exists due to a type confusion error within the iCal implementation in icaltimezone_get_vtimezone_properties function in icalproperty.c. A remote attacker can create a specially crafted email with malformed timezone data, trigger a type confusion error and crash the application.