CVE-2021-29956
Description
OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the users local disk. The master password protection was inactive for those keys. Version 78.10.2 will restore the protection mechanism for newly imported keys, and will automatically protect keys that had been imported using affected Thunderbird versions. This vulnerability affects Thunderbird < 78.10.2.
Risk Information
Base Score
4.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.133
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2021-29957,CVE-2021-29956 are fixed in Mozilla Thunderbird (78.10.2) | Windows |
| Vulnerabilities CVE-2021-29957,CVE-2021-29956 are fixed in Mozilla Thunderbird (x64) (78.10.2) | Windows |
| Vulnerabilities CVE-2021-29956,CVE-2021-29957 are affected in Mozilla Thunderbird 78.10.1 | Windows |
| Vulnerabilities CVE-2021-29957,CVE-2021-29956 are fixed in Mozilla Thunderbird For Mac 78.10.2 | Mac |
| Vulnerabilities CVE-2021-29956,CVE-2021-29957 are affected in Mozilla Thunderbird for Mac 78.10.1 | Mac |
| thunderbird security update(DSA-4927-1) thunderbird_78.11.0-1~deb10u1_i386.deb | Linux |
| thunderbird security update(DSA-4927-1) thunderbird_78.11.0-1~deb10u1_amd64.deb | Linux |
| (RHSA-2021:2264) thunderbird security update thunderbird-78.11.0-1.el8_4.x86_64.rpm | Linux |
| (RHSA-2021:2264) thunderbird security update thunderbird-debugsource-78.11.0-1.el8_4.x86_64.rpm | Linux |
| Mozilla Open Source mail and newsgroup client (USN-4995-1) thunderbird_78.11.0+build1-0ubuntu0.20.04.2_amd64.deb | Linux |
| Mozilla Open Source mail and newsgroup client (USN-4995-1) thunderbird_78.11.0+build1-0ubuntu0.20.10.2_amd64.deb | Linux |
| Mozilla Open Source mail and newsgroup client (USN-4995-1) thunderbird_78.11.0+build1-0ubuntu0.21.04.2_amd64.deb | Linux |
| Mozilla Open Source mail and newsgroup client (USN-4995-2) thunderbird_78.11.0+build1-0ubuntu0.18.04.2_i386.deb | Linux |
| Mozilla Open Source mail and newsgroup client (USN-4995-2) thunderbird_78.11.0+build1-0ubuntu0.18.04.2_amd64.deb | Linux |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-319641 | Mozilla Thunderbird (78.10.2) |
| PATCH-319642 | Mozilla Thunderbird (x64) (78.10.2) |
| PATCH-611807 | Mozilla Thunderbird For Mac (142.0) |
| PATCH-611807 | Mozilla Thunderbird For Mac (142.0) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234