PT-2021-3103 · Mozilla+8 · Thunderbird+8

Wayne Mery

+1

·

Published

2021-05-17

·

Updated

2024-06-15

·

CVE-2021-29957

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 78.10.2
Description The issue arises when a MIME encoded email contains an OpenPGP inline signed or encrypted message part, along with an additional unprotected part. In such cases, Thunderbird fails to indicate that only parts of the message are protected. This is due to insufficient security measures implemented in the email client. An attacker could exploit this by sending a specially crafted email, potentially affecting data integrity.
Recommendations For versions prior to 78.10.2, update to version 78.10.2 or later to resolve the issue.

Exploit

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1829
ALT-PU-2021-1886
ALT-PU-2021-1892
BDU:2021-02726
CESA-2021_2264
CVE-2021-29957
DLA-2679-1
DSA-4927-1
MGASA-2021-0217
OPENSUSE-SU-2021:1854-1
OPENSUSE-SU-2021_1854-1
OPENSUSE-SU-2024:10601-1
RHSA-2021:2261
RHSA-2021:2262
RHSA-2021:2263
RHSA-2021:2264
RHSA-2021_2263
RHSA-2021_2264
RLSA-2021:2264
SUSE-SU-2021:1854-1
USN-4995-1
USN-4995-2

Affected Products

Alt Linux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Thunderbird
Ubuntu