Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-11706. PoCs published by X41 D-Sec GmbH.
AI-analyzed exploit summary The advisory describes a type confusion vulnerability in Thunderbird's libical implementation, which can be triggered by a malformed calendar attachment. The issue arises from improper handling of TZID properties, potentially leading to crashes or information leaks.
Description
A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulting in a crash. This vulnerability affects Thunderbird < 60.7.1.
Exploits (1)
The advisory describes a type confusion vulnerability in Thunderbird's libical implementation, which can be triggered by a malformed calendar attachment. The issue arises from improper handling of TZID properties, potentially leading to crashes or information leaks.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H