CVE-2021-29950
published 2021-06-24CVE-2021-29950: Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.85%
54.6th percentile
Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. This vulnerability affects Thunderbird < 78.8.1.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:78.9.0-1 (bookworm) | thunderbird 1:78.9.0-1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 78.8.1 | 78.8.1 |
| mozilla | thunderbird | >= 0 < 1:78.9.0-1 | 1:78.9.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.9.0-1 | 1:78.9.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.9.0-1 | 1:78.9.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.9.0-1 | 1:78.9.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.8.1+build1-0ubuntu0.20.04.1 | 1:78.8.1+build1-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= unspecified < 78.8.1 | 78.8.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4ghf-pq62-2jfh: Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task
ghsa_unreviewed·2022-05-24
CVE-2021-29950 [HIGH] CWE-312 GHSA-4ghf-pq62-2jfh: Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task
Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. This vulnerability affects Thunderbird < 78.8.1.
OSV
CVE-2021-29950: Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task
osv·2021-06-24·CVSS 7.5
CVE-2021-29950 [HIGH] CVE-2021-29950: Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task
Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. This vulnerability affects Thunderbird < 78.8.1.
OSV
thunderbird vulnerabilities
osv·2021-05-06·CVSS 4.3
CVE-2021-23968 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, or execute arbitrary code. (CVE-2021-23968,
CVE-2021-23969, CVE-2021-23973, CVE-2021-23978)
It was discovered that Thunderbird may keep key material in memory in some
circumstances. A local attacker could potentially exploit this to obtain
private keys. (CVE-2021-29950)
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2021-05-06·CVSS 4.3
CVE-2021-23969 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, or execute arbitrary code. (CVE-2021-23968,
CVE-2021-23969, CVE-2021-23973, CVE-2021-23978)
It was discovered that Thunderbird may keep key material in memory in some
circumstances. A local attacker could potentially exploit this to obtain
private keys. (CVE-2021-29950)
Instructions: After a standard system update you need to restart Thunderbird to make
all the necessary changes.
Red Hat
Mozilla: Logic issue potentially leaves key material unlocked
vendor_redhat·2021-03-08·CVSS 7.5
CVE-2021-29950 [HIGH] CWE-522 Mozilla: Logic issue potentially leaves key material unlocked
Mozilla: Logic issue potentially leaves key material unlocked
Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. This vulnerability affects Thunderbird < 78.8.1.
Package: thunderbird (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2021-29950: thunderbird - Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, ...
vendor_debian·2021·CVSS 7.5
CVE-2021-29950 [HIGH] CVE-2021-29950: thunderbird - Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, ...
Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. This vulnerability affects Thunderbird < 78.8.1.
Scope: local
bookworm: resolved (fixed in 1:78.9.0-1)
bullseye: resolved (fixed in 1:78.9.0-1)
forky: resolved (fixed in 1:78.9.0-1)
sid: resolved (fixed in 1:78.9.0-1)
trixie: resolved (fixed in 1:78.9.0-1)
Mozilla
Mozilla Foundation Security Advisory 2021-17: CVE-2021-29950
vendor_mozilla·CVSS 7.5
CVE-2021-29950 [HIGH] Mozilla Foundation Security Advisory 2021-17: CVE-2021-29950
Mozilla Foundation Security Advisory 2021-17
CVE: CVE-2021-29950
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 78.8.1
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-06-24
Published