If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice. This vulnerability affects Thunderbird < 78.9.1.
CVSS Details
- CVSS 3.1 Base Score: 6.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | May 4, 2022 | Jun 24, 2021 |
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | May 26, 2021 | May 26, 2021 |
| Centos_linux | — | Upgrade thunderbird-debuginfoUpgrade thunderbirdUpgrade thunderbird-debugsource | Apr 15, 2021 | Apr 14, 2021 |
| Debian | — | Upgrade thunderbird | Apr 23, 2021 | Apr 23, 2021 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 78.9.1 | Apr 9, 2021 | Apr 8, 2021 |
| Oracle Solaris | — | Upgrade web/browser/firefox to version 78.10.0-11.4.34.0.1.94.3 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 78.10.0-11.4.34.0.1.94.3 on Solaris 11.4Upgrade mail/thunderbird to version 78.10.0-11.4.34.0.1.94.3 on Solaris 11.4 | Jun 16, 2021 | Jun 16, 2021 |
| Oracle_linux | — | Upgrade thunderbird | Apr 15, 2021 | Apr 8, 2021 |
| Redhat_linux | — | Upgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceNo solution exists | Apr 15, 2021 | Apr 14, 2021 |
| Suse | — | Upgrade mozillathunderbird-translations-commonUpgrade mozillathunderbird-translations-otherUpgrade mozillathunderbird | Apr 20, 2021 | Apr 13, 2021 |
| Ubuntu | — | Upgrade thunderbird | Jun 23, 2021 | Apr 15, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub