CVE-2021-23993Improper Verification of Cryptographic Signature in Mozilla Thunderbird

Severity
6.5MEDIUMNVD
OSV7.4
EPSS
0.1%
top 84.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 24
Latest updateApr 18

Description

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird user imports the crafted key, then Thunderbird may try to use the invalid subkey, but the RNP library rejects it from being used, causing encryption to fail. This vulnerability affects Thunderbird < 78.9.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

debiandebian/thunderbird< thunderbird 1:78.10.0-1 (bookworm)
CVEListV5mozilla/thunderbirdunspecified78.9.1
NVDmozilla/thunderbird< 78.9.1
Debianmozilla/thunderbird< 1:78.10.0-1+3
Ubuntumozilla/thunderbird< 1:78.11.0+build1-0ubuntu0.18.04.2+1

🔴Vulnerability Details

5
GHSA
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade2026-04-18
GHSA
GHSA-3pj2-rvj5-6646: An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent2022-05-24
OSV
thunderbird vulnerabilities2021-06-25
OSV
CVE-2021-23993: An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent2021-06-24
OSV
thunderbird vulnerabilities2021-06-22

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2021-06-25
Ubuntu
Thunderbird vulnerabilities2021-06-22
Red Hat
Mozilla: Inability to send encrypted OpenPGP email after importing a crafted OpenPGP key2021-04-08
Debian
CVE-2021-23993: thunderbird - An attacker may perform a DoS attack to prevent a user from sending encrypted em...2021
Mozilla
Mozilla Foundation Security Advisory 2021-13: CVE-2021-23993