CVE-2021-38502
published 2021-11-03CVE-2021-38502: Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted…
PriorityP432medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.07%
61.3th percentile
Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird < 91.2.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | thunderbird | < thunderbird 1:91.2.1-1 (bookworm) | thunderbird 1:91.2.1-1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 91.2 | 91.2 |
| mozilla | thunderbird | >= 0 < 1:91.4.1-1~deb11u1 | 1:91.4.1-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:91.2.1-1 | 1:91.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:91.2.1-1 | 1:91.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:91.2.1-1 | 1:91.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:91.5.0+build1-0ubuntu0.18.04.1 | 1:91.5.0+build1-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= 0 < 1:91.5.0+build1-0ubuntu0.20.04.1 | 1:91.5.0+build1-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= unspecified < 91.2 | 91.2 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wf24-4m95-7wjm: Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection
ghsa_unreviewed·2022-05-24
CVE-2021-38502 [MEDIUM] CWE-522 GHSA-wf24-4m95-7wjm: Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection
Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird < 91.2.
OSV
thunderbird vulnerabilities
osv·2022-01-21·CVSS 8.8
CVE-2021-4129 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, trick a user into accepting unwanted
permissions, conduct header splitting attacks, conduct spoofing attacks,
bypass security restrictions, confuse the user, or execute arbitrary code.
(CVE-2021-4129, CVE-2021-4140, CVE-2021-29981, CVE-2021-29982,
CVE-2021-29987, CVE-2021-29991, CVE-2021-38495, CVE-2021-38496,
CVE-2021-38497, CVE-2021-38498, CVE-2021-38500, CVE-2021-38501,
CVE-2021-38503, CVE-2021-38504, CVE-2021-38506, CVE-2021-38507,
CVE-2021-38508, CVE-2021-38509, CVE-2021-43534, CVE-2021-43535,
CVE-2021-43536, CVE
OSV
CVE-2021-38502: Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection
osv·2021-11-03·CVSS 5.9
CVE-2021-38502 [MEDIUM] CVE-2021-38502: Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection
Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird < 91.2.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2022-01-21·CVSS 8.8
CVE-2022-22742 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, trick a user into accepting unwanted
permissions, conduct header splitting attacks, conduct spoofing attacks,
bypass security restrictions, confuse the user, or execute arbitrary code.
(CVE-2021-4129, CVE-2021-4140, CVE-2021-29981, CVE-2021-29982,
CVE-2021-29987, CVE-2021-29991, CVE-2021-38495, CVE-2021-38496,
CVE-2021-38497, CVE-2021-38498, CVE-2021-38500, CVE-2021-38501,
CVE-2021-38503, CVE-2021-38504, CVE-2021-38506, CVE-2021-38507,
CVE-2021-38508,
Red Hat
Mozilla: Downgrade attack on SMTP STARTTLS connections
vendor_redhat·2021-10-06·CVSS 5.9
CVE-2021-38502 [MEDIUM] CWE-319 Mozilla: Downgrade attack on SMTP STARTTLS connections
Mozilla: Downgrade attack on SMTP STARTTLS connections
Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird < 91.2.
Package: thunderbird (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2021-38502: thunderbird - Thunderbird ignored the configuration to require STARTTLS security for an SMTP c...
vendor_debian·2021·CVSS 5.9
CVE-2021-38502 [MEDIUM] CVE-2021-38502: thunderbird - Thunderbird ignored the configuration to require STARTTLS security for an SMTP c...
Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird < 91.2.
Scope: local
bookworm: resolved (fixed in 1:91.2.1-1)
bullseye: resolved (fixed in 1:91.4.1-1~deb11u1)
forky: resolved (fixed in 1:91.2.1-1)
sid: resolved (fixed in 1:91.2.1-1)
trixie: resolved (fixed in 1:91.2.1-1)
Mozilla
Mozilla Foundation Security Advisory 2021-47: CVE-2021-38502
vendor_mozilla·CVSS 5.9
CVE-2021-38502 [MEDIUM] Mozilla Foundation Security Advisory 2021-47: CVE-2021-38502
Mozilla Foundation Security Advisory 2021-47
CVE: CVE-2021-38502
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 91.2
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1733366https://lists.debian.org/debian-lts-announce/2022/01/msg00001.htmlhttps://www.debian.org/security/2022/dsa-5034https://www.mozilla.org/security/advisories/mfsa2021-47/https://bugzilla.mozilla.org/show_bug.cgi?id=1733366https://lists.debian.org/debian-lts-announce/2022/01/msg00001.htmlhttps://www.debian.org/security/2022/dsa-5034https://www.mozilla.org/security/advisories/mfsa2021-47/
2021-11-03
Published