{ "id": "CVE-2023-3417", "sourceIdentifier": "security@mozilla.org", "published": "2023-07-24T11:15:09.953", "lastModified": "2023-07-31T04:15:09.987", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1." } ], "metrics": {}, "references": [ { "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1835582", "source": "security@mozilla.org" }, { "url": "https://www.debian.org/security/2023/dsa-5463", "source": "security@mozilla.org" }, { "url": "https://www.mozilla.org/security/advisories/mfsa2023-27/", "source": "security@mozilla.org" }, { "url": "https://www.mozilla.org/security/advisories/mfsa2023-28/", "source": "security@mozilla.org" } ] }