Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Sep 30, 2022 | Sep 30, 2022 |
| Centos_linux | — | Upgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceUpgrade thunderbird | May 26, 2022 | Nov 4, 2021 |
| Debian | — | Upgrade thunderbird | Jan 4, 2022 | Jan 4, 2022 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird.Upgrade mail-client/thunderbird-bin. | Aug 11, 2022 | Aug 10, 2022 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 91.3 | Jan 24, 2023 | Nov 3, 2021 |
| Redhat_linux | — | Upgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoNo solution exists | May 24, 2022 | Nov 4, 2021 |
| Rocky_linux | — | Upgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfo | Mar 12, 2024 | Feb 16, 2023 |
| Ubuntu | — | Upgrade thunderbird | Nov 19, 2024 | Feb 16, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub