CVE-2021-38502
Summary
| CVE | CVE-2021-38502 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-03 01:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird < 91.2. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Vulnerabilities fixed in Thunderbird 91.2 — Mozilla | MISC | www.mozilla.org | |
| Debian -- Security Information -- DSA-5034-1 thunderbird | DEBIAN | www.debian.org | |
| [SECURITY] [DLA 2874-1] thunderbird security update | MLIST | lists.debian.org | |
| Access Denied | MISC | bugzilla.mozilla.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159429 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-3838)
- 159430 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-3841)
- 178983 Debian Security Update for thunderbird (DSA 5034-1)
- 178986 Debian Security Update for thunderbird (DLA 2874-1)
- 184343 Debian Security Update for thunderbird (CVE-2021-38502)
- 198641 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5248-1)
- 239682 Red Hat Update for thunderbird (RHSA-2021:3841)
- 239683 Red Hat Update for thunderbird (RHSA-2021:3840)
- 239684 Red Hat Update for thunderbird (RHSA-2021:3839)
- 239685 Red Hat Update for thunderbird (RHSA-2021:3838)
- 257126 CentOS Security Update for thunderbird (CESA-2021:3841)
- 296066 Oracle Solaris 11.4 Support Repository Update (SRU) 40.107.3 Missing (CPUOCT2021)
- 353982 Amazon Linux Security Advisory for thunderbird : ALAS2-2022-1818
- 375959 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2021-47)
- 502381 Alpine Linux Security Update for thunderbird
- 503632 Alpine Linux Security Update for thunderbird
- 503634 Alpine Linux Security Update for thunderbird
- 503650 Alpine Linux Security Update for thunderbird
- 503669 Alpine Linux Security Update for thunderbird
- 506260 Alpine Linux Security Update for thunderbird
- 751542 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:4150-1)
- 751566 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:1635-1)
- 940268 AlmaLinux Security Update for thunderbird (ALSA-2021:3838)
- 960020 Rocky Linux Security Update for thunderbird (RLSA-2021:3838)