CVE-2023-29479: Medium severity ribose rnp vulnerability
Certain malformed OpenPGP messages could trigger incorrect parsing of PKESK/SKESK packets due to a bug in the Ribose RNP library used by Thunderbird up to version 102.9.1, which would cause the Thunderbird user interface to hang. The issue was discovered using Google's oss-fuzz.
Other sources
Ribose RNP before 0.16.3 may hang when the input is malformed.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-29479?
CVE-2023-29479 is a vulnerability in the Ribose RNP library used by Thunderbird, which could cause the Thunderbird user interface to hang when handling certain malformed OpenPGP messages.
How does CVE-2023-29479 affect Thunderbird?
CVE-2023-29479 affects Thunderbird versions up to 102.9.1, causing the user interface to hang when processing certain malformed OpenPGP messages.
What is the severity of CVE-2023-29479?
CVE-2023-29479 has a medium severity rating.
How can CVE-2023-29479 be fixed?
To fix CVE-2023-29479, update Thunderbird to version 102.10 or later.
Where can I find more information about CVE-2023-29479?
More information about CVE-2023-29479 can be found in the following references: [Link 1](https://www.rnpgp.org/blog/2023-04-13-rnp-release-0-16-3/), [Link 2](https://cve.ribose.com/advisories/ra-2023-04-11/), [Link 3](https://launchpad.net/bugs/cve/CVE-2023-29479)