CVE-2021-38502

Description

Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird < 91.2.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.461

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in Mozilla Thunderbird (91) (x64) (91.2.0)Windows
Multiple vulnerabilities fixed in Mozilla Thunderbird (91) (91.2.0)Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 91.1Windows
Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac 91.2Mac
Multiple Vulnerabilities are affected in Mozilla Thunderbird for Mac 91.1Mac
(RHSA-2021:3841) thunderbird security update thunderbird-91.2.0-1.el7_9.x86_64.rpmLinux
Thunderbird update (ELSA-2021-3838) thunderbird-91.2.0-1.0.1.el8_4.x86_64.rpmLinux
Thunderbird update (ELSA-2021-3841) thunderbird-91.2.0-1.0.1.el7_9.x86_64.rpmLinux
thunderbird security update(DSA-5034-1) thunderbird_91.4.1-1~deb10u1_i386.debLinux
thunderbird security update(DSA-5034-1) thunderbird_91.4.1-1~deb10u1_amd64.debLinux
thunderbird security update(DSA-5034-1) thunderbird_91.4.1-1~deb11u1_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-5248-1) thunderbird_91.5.0+build1-0ubuntu0.18.04.1_i386.debLinux
Mozilla Open Source mail and newsgroup client (USN-5248-1) thunderbird_91.5.0+build1-0ubuntu0.18.04.1_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-5248-1) thunderbird_91.5.0+build1-0ubuntu0.20.04.1_amd64.debLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-321786Mozilla Thunderbird (91) (x64) (91.2.0)
PATCH-321775Mozilla Thunderbird (91) (91.2.0)
PATCH-611807Mozilla Thunderbird For Mac (142.0)
PATCH-611807Mozilla Thunderbird For Mac (142.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234