Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. This vulnerability affects Thunderbird < 78.8.1.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-thunderbird | May 4, 2022 | Jun 24, 2021 | |
| Centos_linux | — | centos-upgrade-thunderbirdcentos-upgrade-thunderbird-debuginfocentos-upgrade-thunderbird-debugsource | Jun 1, 2021 | Apr 14, 2021 |
| Debian | debian-upgrade-thunderbird | Apr 23, 2021 | Apr 23, 2021 | |
| Mozilla Thunderbird | mozilla-thunderbird-upgrade-78_8_1 | Apr 21, 2021 | Mar 8, 2021 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-mail-thunderbird-78-9-0-11-4-32-0-1-88-3 | Jun 16, 2021 | Jun 16, 2021 | |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-thunderbirdredhat-upgrade-thunderbird-debuginforedhat-upgrade-thunderbird-debugsource | Apr 28, 2021 | Apr 14, 2021 | |
| Suse | — | suse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-other | Jun 9, 2021 | May 6, 2021 |
| Ubuntu | ubuntu-upgrade-thunderbird | May 7, 2021 | May 6, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub