CVE-2021-43529
published 2023-02-16CVE-2021-43529: Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions…
PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.47%
38.0th percentile
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:91.3.0-1 (bookworm) | thunderbird 1:91.3.0-1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 91.3.0 | 91.3.0 |
| mozilla | thunderbird | >= 0 < 1:91.4.1-1~deb11u1 | 1:91.4.1-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:91.3.0-1 | 1:91.3.0-1 |
| mozilla | thunderbird | >= 0 < 1:91.3.0-1 | 1:91.3.0-1 |
| mozilla | thunderbird | >= 0 < 1:91.3.0-1 | 1:91.3.0-1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
thunderbird: Memory corruption when processing S/MIME messages
vendor_redhat·2021-12-01·CVSS 9.8
CVE-2021-43529 [CRITICAL] CWE-120 thunderbird: Memory corruption when processing S/MIME messages
thunderbird: Memory corruption when processing S/MIME messages
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
A flaw was found in Thunderbird, which is vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
Statement: Thunderbird is affected when parsing email with the S/MIME signature. Thunderbird on Red Hat Enterprise Li
Debian
CVE-2021-43529: thunderbird - Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow describ...
vendor_debian·2021·CVSS 9.8
CVE-2021-43529 [CRITICAL] CVE-2021-43529: thunderbird - Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow describ...
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
Scope: local
bookworm: resolved (fixed in 1:91.3.0-1)
bullseye: resolved (fixed in 1:91.4.1-1~deb11u1)
forky: resolved (fixed in 1:91.3.0-1)
sid: resolved (fixed in 1:91.3.0-1)
trixie: resolved (fixed in 1:91.3.0-1)
Mozilla
Mozilla Foundation Security Advisory 2021-50: CVE-2021-43529
vendor_mozilla·CVSS 9.8
CVE-2021-43529 [CRITICAL] Mozilla Foundation Security Advisory 2021-50: CVE-2021-43529
Mozilla Foundation Security Advisory 2021-50
CVE: CVE-2021-43529
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 91.3
GHSA
GHSA-82q7-2fg2-4gcj: Thunderbird versions prior to 91
ghsa_unreviewed·2023-02-17·CVSS 9.8
CVE-2021-43529 [CRITICAL] CWE-787 GHSA-82q7-2fg2-4gcj: Thunderbird versions prior to 91
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
OSV
CVE-2021-43529: Thunderbird versions prior to 91
osv·2023-02-16·CVSS 9.8
CVE-2021-43529 [CRITICAL] CVE-2021-43529: Thunderbird versions prior to 91
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
No detection rules found.
No public exploits indexed.
2023-02-16
Published