CVE-2021-29957

Description

If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indicate that only parts of the message are protected. This vulnerability affects Thunderbird < 78.10.2.

Risk Information

Base Score
4.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS Score
Exploitation Probability
0.305

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-29957,CVE-2021-29956 are fixed in Mozilla Thunderbird (78.10.2)Windows
Vulnerabilities CVE-2021-29957,CVE-2021-29956 are fixed in Mozilla Thunderbird (x64) (78.10.2)Windows
Vulnerabilities CVE-2021-29956,CVE-2021-29957 are affected in Mozilla Thunderbird 78.10.1Windows
Vulnerabilities CVE-2021-29957,CVE-2021-29956 are fixed in Mozilla Thunderbird For Mac 78.10.2Mac
Vulnerabilities CVE-2021-29956,CVE-2021-29957 are affected in Mozilla Thunderbird for Mac 78.10.1Mac
thunderbird security update(DSA-4927-1) thunderbird_78.11.0-1~deb10u1_i386.debLinux
thunderbird security update(DSA-4927-1) thunderbird_78.11.0-1~deb10u1_amd64.debLinux
(RHSA-2021:2264) thunderbird security update thunderbird-78.11.0-1.el8_4.x86_64.rpmLinux
(RHSA-2021:2264) thunderbird security update thunderbird-debugsource-78.11.0-1.el8_4.x86_64.rpmLinux
Mozilla Open Source mail and newsgroup client (USN-4995-1) thunderbird_78.11.0+build1-0ubuntu0.20.04.2_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-4995-1) thunderbird_78.11.0+build1-0ubuntu0.20.10.2_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-4995-1) thunderbird_78.11.0+build1-0ubuntu0.21.04.2_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-4995-2) thunderbird_78.11.0+build1-0ubuntu0.18.04.2_i386.debLinux
Mozilla Open Source mail and newsgroup client (USN-4995-2) thunderbird_78.11.0+build1-0ubuntu0.18.04.2_amd64.debLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-319641Mozilla Thunderbird (78.10.2)
PATCH-319642Mozilla Thunderbird (x64) (78.10.2)
PATCH-611807Mozilla Thunderbird For Mac (142.0)
PATCH-611807Mozilla Thunderbird For Mac (142.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234