CVE-2021-29969
published 2021-08-05CVE-2021-29969: If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS…
PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.20%
64.7th percentile
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. This could have resulted in Thunderbird showing incorrect information, for example the attacker could have tricked Thunderbird to show folders that didn't exist on the IMAP server. This vulnerability affects Thunderbird < 78.12.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:78.12.0-1 (bookworm) | thunderbird 1:78.12.0-1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 78.12 | 78.12 |
| mozilla | thunderbird | >= 0 < 1:78.12.0-1 | 1:78.12.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.12.0-1 | 1:78.12.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.12.0-1 | 1:78.12.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.12.0-1 | 1:78.12.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.13.0+build1-0ubuntu0.18.04.1 | 1:78.13.0+build1-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= 0 < 1:78.13.0+build1-0ubuntu0.20.04.2 | 1:78.13.0+build1-0ubuntu0.20.04.2 |
| mozilla | thunderbird | >= unspecified < 78.12 | 78.12 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2021-08-31·CVSS 5.9
CVE-2021-29985 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
It was discovered that Thunderbird didn't ignore IMAP server responses
prior to completion of the STARTTLS handshake. A person-in-the-middle
could potentially exploit this to trick Thunderbird into showing incorrect
information. (CVE-2021-29969)
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service, or
execute arbitrary code. (CVE-2021-29970, CVE-2021-29976, CVE-2021-29980,
CVE-2021-29984, CVE-2021-29985, CVE-2021-29986, CVE-2021-29988,
CVE-2021-29989, CVE-2021-30547)
Instructions: After a standard system update you need to restart
Red Hat
Mozilla: IMAP server responses sent by a MITM prior to STARTTLS could be processed
vendor_redhat·2021-07-13·CVSS 5.9
CVE-2021-29969 [MEDIUM] CWE-345 Mozilla: IMAP server responses sent by a MITM prior to STARTTLS could be processed
Mozilla: IMAP server responses sent by a MITM prior to STARTTLS could be processed
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. This could have resulted in Thunderbird showing incorrect information, for example the attacker could have tricked Thunderbird to show folders that didn't exist on the IMAP server. This vulnerability affects Thunderbird < 78.12.
Package: thunderbird (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2021-29969: thunderbird - If Thunderbird was configured to use STARTTLS for an IMAP connection, and an att...
vendor_debian·2021·CVSS 5.9
CVE-2021-29969 [MEDIUM] CVE-2021-29969: thunderbird - If Thunderbird was configured to use STARTTLS for an IMAP connection, and an att...
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. This could have resulted in Thunderbird showing incorrect information, for example the attacker could have tricked Thunderbird to show folders that didn't exist on the IMAP server. This vulnerability affects Thunderbird < 78.12.
Scope: local
bookworm: resolved (fixed in 1:78.12.0-1)
bullseye: resolved (fixed in 1:78.12.0-1)
forky: resolved (fixed in 1:78.12.0-1)
sid: resolved (fixed in 1:78.12.0-1)
trixie: resolved (fixed in 1:78.12.0-1)
Mozilla
Mozilla Foundation Security Advisory 2021-30: CVE-2021-29969
vendor_mozilla·CVSS 5.9
CVE-2021-29969 [MEDIUM] Mozilla Foundation Security Advisory 2021-30: CVE-2021-29969
Mozilla Foundation Security Advisory 2021-30
CVE: CVE-2021-29969
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 78.12
GHSA
GHSA-ggp3-c9px-5c4p: If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the ST
ghsa_unreviewed·2022-05-24
CVE-2021-29969 [MEDIUM] CWE-552 GHSA-ggp3-c9px-5c4p: If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the ST
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. This could have resulted in Thunderbird showing incorrect information, for example the attacker could have tricked Thunderbird to show folders that didn't exist on the IMAP server. This vulnerability affects Thunderbird < 78.12.
OSV
thunderbird vulnerabilities
osv·2021-08-31·CVSS 5.9
CVE-2021-29969 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
It was discovered that Thunderbird didn't ignore IMAP server responses
prior to completion of the STARTTLS handshake. A person-in-the-middle
could potentially exploit this to trick Thunderbird into showing incorrect
information. (CVE-2021-29969)
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service, or
execute arbitrary code. (CVE-2021-29970, CVE-2021-29976, CVE-2021-29980,
CVE-2021-29984, CVE-2021-29985, CVE-2021-29986, CVE-2021-29988,
CVE-2021-29989, CVE-2021-30547)
OSV
CVE-2021-29969: If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the ST
osv·2021-08-05·CVSS 5.9
CVE-2021-29969 [MEDIUM] CVE-2021-29969: If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the ST
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. This could have resulted in Thunderbird showing incorrect information, for example the attacker could have tricked Thunderbird to show folders that didn't exist on the IMAP server. This vulnerability affects Thunderbird < 78.12.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1682370https://security.gentoo.org/glsa/202208-14https://www.mozilla.org/security/advisories/mfsa2021-30/https://bugzilla.mozilla.org/show_bug.cgi?id=1682370https://security.gentoo.org/glsa/202208-14https://www.mozilla.org/security/advisories/mfsa2021-30/
2021-08-05
Published