CVE-2021-23991Improper Verification of Cryptographic Signature in Mozilla Thunderbird

Severity
6.8MEDIUMNVD
OSV7.4
EPSS
0.2%
top 57.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 24
Latest updateMay 24

Description

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice. This vulnerability affects Thunderbird < 78.9.1.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:NExploitability: 1.6 | Impact: 5.2

Affected Packages6 packages

debiandebian/thunderbird< thunderbird 1:78.10.0-1 (bookworm)
CVEListV5mozilla/thunderbirdunspecified78.9.1
NVDmozilla/thunderbird< 78.9.1
Debianmozilla/thunderbird< 1:78.10.0-1+3
Ubuntumozilla/thunderbird< 1:78.11.0+build1-0ubuntu0.18.04.2+1

🔴Vulnerability Details

4
GHSA
GHSA-x5j6-p8w8-5r65: If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has2022-05-24
OSV
thunderbird vulnerabilities2021-06-25
OSV
CVE-2021-23991: If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has2021-06-24
OSV
thunderbird vulnerabilities2021-06-22

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2021-06-25
Ubuntu
Thunderbird vulnerabilities2021-06-22
Red Hat
Mozilla: An attacker may use Thunderbird's OpenPGP key refresh mechanism to poison an existing key2021-04-08
Debian
CVE-2021-23991: thunderbird - If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has...2021
Mozilla
Mozilla Foundation Security Advisory 2021-13: CVE-2021-23991