When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distributed by Thunderbird. If a computer has already been infected with a malicious library of the alternative filename, and the malicious library has been copied to a directory that is contained in the search path for executable libraries, then Thunderbird will load the incorrect library. This vulnerability affects Thunderbird < 78.9.1.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | May 4, 2022 | Jun 24, 2021 |
| Centos_linux | — | Upgrade thunderbird-debugsourceUpgrade thunderbirdUpgrade thunderbird-debuginfo | Jun 1, 2021 | Apr 14, 2021 |
| Debian | — | Upgrade thunderbird | Apr 23, 2021 | Apr 23, 2021 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 78.9.1 | Apr 21, 2021 | Apr 8, 2021 |
| Oracle Solaris | — | Upgrade mail/thunderbird to version 78.10.0-11.4.34.0.1.94.3 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 78.10.0-11.4.34.0.1.94.3 on Solaris 11.4Upgrade web/browser/firefox to version 78.10.0-11.4.34.0.1.94.3 on Solaris 11.4 | Jun 16, 2021 | Jun 16, 2021 |
| Redhat_linux | — | Upgrade thunderbird-debugsourceUpgrade thunderbirdNo solution existsUpgrade thunderbird-debuginfo | Apr 23, 2021 | Apr 14, 2021 |
| Ubuntu | — | Upgrade thunderbird | Jun 23, 2021 | Jun 22, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub