An incorrect type conversion of sizes from 64bit to 32bit...
High severity
Unreviewed
Published
Dec 9, 2021
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Dec 8, 2021
Published to the GitHub Advisory Database
Dec 9, 2021
Last updated
Jan 29, 2023
An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
References