CVE-2021-23991
Summary
| CVE | CVE-2021-23991 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-24 14:15:00 UTC |
| Updated | 2021-07-08 15:50:00 UTC |
| Description | If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice. This vulnerability affects Thunderbird < 78.9.1. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Thunderbird | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1673240 - (CVE-2021-23991) RNP-01-014 WP1 Thunderbird: Key manipulation via uncertified Auto-Import (Medium) | MISC | bugzilla.mozilla.org | |
| Security Vulnerabilities fixed in Thunderbird 78.9.1 — Mozilla | MISC | www.mozilla.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159147 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-1192)
- 159148 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-1193)
- 178561 Debian Security Update for thunderbird (DSA 4897-1)
- 178644 Debian Security Update for thunderbird (DLA 2632-1)
- 179921 Debian Security Update for thunderbird (CVE-2021-23991)
- 198415 Ubuntu Security Notification for Thunderbird vulnerabilities (USN-4995-1)
- 198424 Ubuntu Security Notification for Thunderbird vulnerabilities (USN-4995-2)
- 239221 Red Hat Update for thunderbird (RHSA-2021:1201)
- 239223 Red Hat Update for thunderbird (RHSA-2021:1193)
- 239224 Red Hat Update for thunderbird (RHSA-2021:1192)
- 239225 Red Hat Update for thunderbird (RHSA-2021:1190)
- 257078 CentOS Security Update for thunderbird (CESA-2021:1192)
- 296068 Oracle Solaris 11.4 Support Repository Update (SRU) 34.94.4 Missing (CPUAPR2021)
- 352368 Amazon Linux Security Advisory for thunderbird: ALAS2-2021-1644
- 375465 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2021-13)
- 750260 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:0580-1)
- 940242 AlmaLinux Security Update for thunderbird (ALSA-2021:1193)