CVE-2021-29956

Description

OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the users local disk. The master password protection was inactive for those keys. Version 78.10.2 will restore the protection mechanism for newly imported keys, and will automatically protect keys that had been imported using affected Thunderbird versions. This vulnerability affects Thunderbird < 78.10.2.

Risk Information

Base Score
4.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.133

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-29957,CVE-2021-29956 are fixed in Mozilla Thunderbird (78.10.2)Windows
Vulnerabilities CVE-2021-29957,CVE-2021-29956 are fixed in Mozilla Thunderbird (x64) (78.10.2)Windows
Vulnerabilities CVE-2021-29956,CVE-2021-29957 are affected in Mozilla Thunderbird 78.10.1Windows
Vulnerabilities CVE-2021-29957,CVE-2021-29956 are fixed in Mozilla Thunderbird For Mac 78.10.2Mac
Vulnerabilities CVE-2021-29956,CVE-2021-29957 are affected in Mozilla Thunderbird for Mac 78.10.1Mac
thunderbird security update(DSA-4927-1) thunderbird_78.11.0-1~deb10u1_i386.debLinux
thunderbird security update(DSA-4927-1) thunderbird_78.11.0-1~deb10u1_amd64.debLinux
(RHSA-2021:2264) thunderbird security update thunderbird-78.11.0-1.el8_4.x86_64.rpmLinux
(RHSA-2021:2264) thunderbird security update thunderbird-debugsource-78.11.0-1.el8_4.x86_64.rpmLinux
Mozilla Open Source mail and newsgroup client (USN-4995-1) thunderbird_78.11.0+build1-0ubuntu0.20.04.2_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-4995-1) thunderbird_78.11.0+build1-0ubuntu0.20.10.2_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-4995-1) thunderbird_78.11.0+build1-0ubuntu0.21.04.2_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-4995-2) thunderbird_78.11.0+build1-0ubuntu0.18.04.2_i386.debLinux
Mozilla Open Source mail and newsgroup client (USN-4995-2) thunderbird_78.11.0+build1-0ubuntu0.18.04.2_amd64.debLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-319641Mozilla Thunderbird (78.10.2)
PATCH-319642Mozilla Thunderbird (x64) (78.10.2)
PATCH-611807Mozilla Thunderbird For Mac (142.0)
PATCH-611807Mozilla Thunderbird For Mac (142.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234