cbcvebase.
CVE-2021-23991
published 2021-06-24

CVE-2021-23991: If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet…

PriorityP431medium6.8CVSS 3.1
AVNACHPRNUIRSUCHIHAN
EPSS
1.03%
60.4th percentile
If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice. This vulnerability affects Thunderbird < 78.9.1.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianthunderbird< thunderbird 1:78.10.0-1 (bookworm)thunderbird 1:78.10.0-1 (bookworm)
mozillafirefox
mozillathunderbird< 78.9.178.9.1
mozillathunderbird>= 0 < 1:78.10.0-11:78.10.0-1
mozillathunderbird>= 0 < 1:78.10.0-11:78.10.0-1
mozillathunderbird>= 0 < 1:78.10.0-11:78.10.0-1
mozillathunderbird>= 0 < 1:78.10.0-11:78.10.0-1
mozillathunderbird>= 0 < 1:78.11.0+build1-0ubuntu0.18.04.21:78.11.0+build1-0ubuntu0.18.04.2
mozillathunderbird>= 0 < 1:78.11.0+build1-0ubuntu0.20.04.21:78.11.0+build1-0ubuntu0.20.04.2
mozillathunderbird>= unspecified < 78.9.178.9.1

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv7.4HIGH
vendor_ubuntu7.4HIGH
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.