PT-2021-7423 · Mozilla+5 · Thunderbird+5
Kai Engert
·
Published
2021-12-21
·
Updated
2024-06-15
·
CVE-2021-4126
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Thunderbird versions prior to 91.4.1
Description
The issue is related to how Thunderbird handles OpenPGP/MIME signed email messages with additional outer MIME message layers. Previously, Thunderbird only considered the inner signed message for signature validity, giving the false impression that the additional contents were also covered by the digital signature. This could allow a remote attacker to perform a spoofing attack due to insufficient warning about dangerous actions.
Recommendations
For Thunderbird versions prior to 91.4.1, update to version 91.4.1 or later to ensure that only the signature belonging to the top-level MIME part is considered for the displayed status, thus preventing the false impression of additional contents being covered by the digital signature.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Suse
Thunderbird
Ubuntu