CVE-2021-23992
Summary
| CVE | CVE-2021-23992 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-24 14:15:00 UTC |
| Updated | 2021-07-08 15:47:00 UTC |
| Description | Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to the correspondent. This vulnerability affects Thunderbird < 78.9.1. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Mozilla |
Thunderbird |
All |
All |
All |
All |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159147 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-1192)
- 159148 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-1193)
- 178561 Debian Security Update for thunderbird (DSA 4897-1)
- 178644 Debian Security Update for thunderbird (DLA 2632-1)
- 180183 Debian Security Update for thunderbird (CVE-2021-23992)
- 198415 Ubuntu Security Notification for Thunderbird vulnerabilities (USN-4995-1)
- 198424 Ubuntu Security Notification for Thunderbird vulnerabilities (USN-4995-2)
- 239221 Red Hat Update for thunderbird (RHSA-2021:1201)
- 239223 Red Hat Update for thunderbird (RHSA-2021:1193)
- 239224 Red Hat Update for thunderbird (RHSA-2021:1192)
- 239225 Red Hat Update for thunderbird (RHSA-2021:1190)
- 257078 CentOS Security Update for thunderbird (CESA-2021:1192)
- 296068 Oracle Solaris 11.4 Support Repository Update (SRU) 34.94.4 Missing (CPUAPR2021)
- 352368 Amazon Linux Security Advisory for thunderbird: ALAS2-2021-1644
- 375465 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2021-13)
- 750260 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:0580-1)
- 940242 AlmaLinux Security Update for thunderbird (ALSA-2021:1193)