Address Parsing Vulnerability in Thunderbird Email Client by Mozilla
CVE-2025-3875

7.5HIGH

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
14 May 2025

What is CVE-2025-3875?

In Mozilla Thunderbird, a vulnerability exists in the way addresses are parsed, allowing for potential sender spoofing. When a server permits the use of an invalid 'From' address, Thunderbird may erroneously interpret the spoofed address as legitimate. For instance, if the 'From' header is improperly formatted, like including trailing spaces or unusual characters, it can lead to confusion and misuse, compromising the integrity of email communication. This issue affects users of versions prior to 128.10.1 and 138.0.1.

Affected Version(s)

Thunderbird < 128.10.1

Thunderbird < 138.0.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

xh4vm
.
CVE-2025-3875 : Address Parsing Vulnerability in Thunderbird Email Client by Mozilla