The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade botan | Mar 26, 2024 | Sep 6, 2021 |
| Debian | — | Upgrade botan | Jul 30, 2024 | Sep 6, 2021 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird.Upgrade mail-client/thunderbird-bin. | Aug 11, 2022 | Sep 6, 2021 |
| Suse | — | Upgrade mozillathunderbirdUpgrade mozillathunderbird-translations-otherUpgrade mozillathunderbird-translations-common | Dec 23, 2021 | Sep 6, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub