CVE-2021-29969
Description
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didnt ignore the injected data. This could have resulted in Thunderbird showing incorrect information, for example the attacker could have tricked Thunderbird to show folders that didnt exist on the IMAP server. This vulnerability affects Thunderbird < 78.12.
Risk Information
Base Score
5.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.396
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2021-29969,CVE-2021-29970,CVE-2021-30547,CVE-2021-29976 are fixed in Mozilla Thunderbird (x64) (78.12.0) | Windows |
| Vulnerabilities CVE-2021-29969,CVE-2021-29970,CVE-2021-30547,CVE-2021-29976 are fixed in Mozilla Thunderbird (78.12.0) | Windows |
| Vulnerabilities CVE-2021-29969,CVE-2021-29970,CVE-2021-30547,CVE-2021-29976 are fixed in Mozilla Thunderbird For Mac (78.12.0) | Mac |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird for Mac 78.9.1 | Mac |
| thunderbird security update(DSA-4940-1) thunderbird_78.12.0-1~deb10u1_i386.deb | Linux |
| thunderbird security update(DSA-4940-1) thunderbird_78.12.0-1~deb10u1_amd64.deb | Linux |
| (RHSA-2021:2881) thunderbird security update thunderbird-78.12.0-2.el7_9.x86_64.rpm | Linux |
| Thunderbird update (ELSA-2021-2881) thunderbird-78.12.0-2.0.1.el7_9.x86_64.rpm | Linux |
| (RHSA-2021:2883) thunderbird security update thunderbird-78.12.0-3.el8_4.x86_64.rpm | Linux |
| (RHSA-2021:2883) thunderbird security update thunderbird-debugsource-78.12.0-3.el8_4.x86_64.rpm | Linux |
| Thunderbird update (ELSA-2021-2883) thunderbird-78.12.0-3.0.1.el8_4.x86_64.rpm | Linux |
| Mozilla Open Source mail and newsgroup client (USN-5058-1) thunderbird_78.13.0+build1-0ubuntu0.18.04.1_i386.deb | Linux |
| Mozilla Open Source mail and newsgroup client (USN-5058-1) thunderbird_78.13.0+build1-0ubuntu0.18.04.1_amd64.deb | Linux |
| Mozilla Open Source mail and newsgroup client (USN-5058-1) thunderbird_78.13.0+build1-0ubuntu0.20.04.2_amd64.deb | Linux |
| Mozilla Open Source mail and newsgroup client (USN-5058-1) thunderbird_78.13.0+build1-0ubuntu0.21.04.2_amd64.deb | Linux |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-320518 | Mozilla Thunderbird (x64) (78.12.0) |
| PATCH-320517 | Mozilla Thunderbird (78.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611807 | Mozilla Thunderbird For Mac (142.0) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234