CVE-2021-29969

Description

If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didnt ignore the injected data. This could have resulted in Thunderbird showing incorrect information, for example the attacker could have tricked Thunderbird to show folders that didnt exist on the IMAP server. This vulnerability affects Thunderbird < 78.12.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.396

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-29969,CVE-2021-29970,CVE-2021-30547,CVE-2021-29976 are fixed in Mozilla Thunderbird (x64) (78.12.0)Windows
Vulnerabilities CVE-2021-29969,CVE-2021-29970,CVE-2021-30547,CVE-2021-29976 are fixed in Mozilla Thunderbird (78.12.0)Windows
Vulnerabilities CVE-2021-29969,CVE-2021-29970,CVE-2021-30547,CVE-2021-29976 are fixed in Mozilla Thunderbird For Mac (78.12.0)Mac
Multiple Vulnerabilities are affected in Mozilla Thunderbird for Mac 78.9.1Mac
thunderbird security update(DSA-4940-1) thunderbird_78.12.0-1~deb10u1_i386.debLinux
thunderbird security update(DSA-4940-1) thunderbird_78.12.0-1~deb10u1_amd64.debLinux
(RHSA-2021:2881) thunderbird security update thunderbird-78.12.0-2.el7_9.x86_64.rpmLinux
Thunderbird update (ELSA-2021-2881) thunderbird-78.12.0-2.0.1.el7_9.x86_64.rpmLinux
(RHSA-2021:2883) thunderbird security update thunderbird-78.12.0-3.el8_4.x86_64.rpmLinux
(RHSA-2021:2883) thunderbird security update thunderbird-debugsource-78.12.0-3.el8_4.x86_64.rpmLinux
Thunderbird update (ELSA-2021-2883) thunderbird-78.12.0-3.0.1.el8_4.x86_64.rpmLinux
Mozilla Open Source mail and newsgroup client (USN-5058-1) thunderbird_78.13.0+build1-0ubuntu0.18.04.1_i386.debLinux
Mozilla Open Source mail and newsgroup client (USN-5058-1) thunderbird_78.13.0+build1-0ubuntu0.18.04.1_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-5058-1) thunderbird_78.13.0+build1-0ubuntu0.20.04.2_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-5058-1) thunderbird_78.13.0+build1-0ubuntu0.21.04.2_amd64.debLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-320518Mozilla Thunderbird (x64) (78.12.0)
PATCH-320517Mozilla Thunderbird (78.12.0)
PATCH-611353Mozilla Thunderbird For Mac (128.12.0)
PATCH-611807Mozilla Thunderbird For Mac (142.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234