PT-2021-7423 · Mozilla+5 · Thunderbird+5

Kai Engert

·

Published

2021-12-21

·

Updated

2024-06-15

·

CVE-2021-4126

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 91.4.1
Description The issue is related to how Thunderbird handles OpenPGP/MIME signed email messages with additional outer MIME message layers. Previously, Thunderbird only considered the inner signed message for signature validity, giving the false impression that the additional contents were also covered by the digital signature. This could allow a remote attacker to perform a spoofing attack due to insufficient warning about dangerous actions.
Recommendations For Thunderbird versions prior to 91.4.1, update to version 91.4.1 or later to ensure that only the signature belonging to the top-level MIME part is considered for the displayed status, thus preventing the false impression of additional contents being covered by the digital signature.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3584
ALT-PU-2021-3625
ALT-PU-2021-3638
ALT-PU-2022-1783
BDU:2022-06100
CVE-2021-4126
DLA-2874-1
DSA-5034-1
MGASA-2021-0584
OPENSUSE-SU-2022:0058-1
OPENSUSE-SU-2022_0058-1
OPENSUSE-SU-2024:11698-1
SUSE-SU-2022:0058-1
USN-5246-1
USN-5248-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Suse
Thunderbird
Ubuntu