CVE-2021-29950
Summary
| CVE | CVE-2021-29950 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-24 14:15:00 UTC |
| Updated | 2021-06-25 20:12:00 UTC |
| Description | Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. This vulnerability affects Thunderbird < 78.8.1. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Mozilla |
Thunderbird |
All |
All |
All |
All |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179596 Debian Security Update for thunderbird (CVE-2021-29950)
- 198355 Ubuntu Security Notification for Thunderbird vulnerabilities (USN-4936-1)
- 257078 CentOS Security Update for thunderbird (CESA-2021:1192)
- 375515 Mozilla Thunderbird Vulnerability (MFSA2021-17)
- 750810 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:1854-1)
- 940242 AlmaLinux Security Update for thunderbird (ALSA-2021:1193)