CVE-2021-38502
Description
Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird < 91.2.
Risk Information
Base Score
5.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.461
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities fixed in Mozilla Thunderbird (91) (x64) (91.2.0) | Windows |
| Multiple vulnerabilities fixed in Mozilla Thunderbird (91) (91.2.0) | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 91.1 | Windows |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac 91.2 | Mac |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird for Mac 91.1 | Mac |
| (RHSA-2021:3841) thunderbird security update thunderbird-91.2.0-1.el7_9.x86_64.rpm | Linux |
| Thunderbird update (ELSA-2021-3838) thunderbird-91.2.0-1.0.1.el8_4.x86_64.rpm | Linux |
| Thunderbird update (ELSA-2021-3841) thunderbird-91.2.0-1.0.1.el7_9.x86_64.rpm | Linux |
| thunderbird security update(DSA-5034-1) thunderbird_91.4.1-1~deb10u1_i386.deb | Linux |
| thunderbird security update(DSA-5034-1) thunderbird_91.4.1-1~deb10u1_amd64.deb | Linux |
| thunderbird security update(DSA-5034-1) thunderbird_91.4.1-1~deb11u1_amd64.deb | Linux |
| Mozilla Open Source mail and newsgroup client (USN-5248-1) thunderbird_91.5.0+build1-0ubuntu0.18.04.1_i386.deb | Linux |
| Mozilla Open Source mail and newsgroup client (USN-5248-1) thunderbird_91.5.0+build1-0ubuntu0.18.04.1_amd64.deb | Linux |
| Mozilla Open Source mail and newsgroup client (USN-5248-1) thunderbird_91.5.0+build1-0ubuntu0.20.04.1_amd64.deb | Linux |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-321786 | Mozilla Thunderbird (91) (x64) (91.2.0) |
| PATCH-321775 | Mozilla Thunderbird (91) (91.2.0) |
| PATCH-611807 | Mozilla Thunderbird For Mac (142.0) |
| PATCH-611807 | Mozilla Thunderbird For Mac (142.0) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234