When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 128.2.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-8394.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "128.2.0" } ] } ]