Skip to content

Commit

Permalink
Add missing OTR CVE
Browse files Browse the repository at this point in the history
  • Loading branch information
tomrittervg committed Sep 6, 2024
1 parent 1c7adcc commit a6bcdbd
Showing 1 changed file with 8 additions and 0 deletions.
8 changes: 8 additions & 0 deletions announce/2024/mfsa2024-43.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,14 @@ title: Security Vulnerabilities fixed in Thunderbird 128.2
description: |
*In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potential risks in browser or browser-like contexts.*
advisories:
CVE-2024-8394:
title: Crash when aborting verification of OTR chat
impact: high
reporter: Thunderbird Team
description: |
When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash.
bugs:
- url: 1895737
CVE-2024-8385:
title: WASM type confusion involving ArrayTypes
impact: high
Expand Down

0 comments on commit a6bcdbd

Please sign in to comment.