CVE-2021-29949
Summary
| CVE | CVE-2021-29949 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-24 14:15:00 UTC |
| Updated | 2021-06-30 17:59:00 UTC |
| Description | When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distributed by Thunderbird. If a computer has already been infected with a malicious library of the alternative filename, and the malicious library has been copied to a directory that is contained in the search path for executable libraries, then Thunderbird will load the incorrect library. This vulnerability affects Thunderbird < 78.9.1. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Mozilla |
Thunderbird |
All |
All |
All |
All |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178561 Debian Security Update for thunderbird (DSA 4897-1)
- 178644 Debian Security Update for thunderbird (DLA 2632-1)
- 180579 Debian Security Update for thunderbird (CVE-2021-29949)
- 198415 Ubuntu Security Notification for Thunderbird vulnerabilities (USN-4995-1)
- 198424 Ubuntu Security Notification for Thunderbird vulnerabilities (USN-4995-2)
- 257078 CentOS Security Update for thunderbird (CESA-2021:1192)
- 296068 Oracle Solaris 11.4 Support Repository Update (SRU) 34.94.4 Missing (CPUAPR2021)
- 940242 AlmaLinux Security Update for thunderbird (ALSA-2021:1193)