CVE-2021-4126
Summary
| CVE | CVE-2021-4126 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-22 20:15:00 UTC |
| Updated | 2023-01-04 14:19:00 UTC |
| Description | When receiving an OpenPGP/MIME signed email message that contains an additional outer MIME message layer, for example a message footer added by a mailing list gateway, Thunderbird only considered the inner signed message for the signature validity. This gave the false impression that the additional contents were also covered by the digital signature. Starting with Thunderbird version 91.4.1, only the signature that belongs to the top level MIME part will be considered for the displayed status. This vulnerability affects Thunderbird < 91.4.1. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Thunderbird | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Access Denied | MISC | bugzilla.mozilla.org | |
| Security Vulnerabilities fixed in Thunderbird 91.4.1 — Mozilla | MISC | www.mozilla.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178983 Debian Security Update for thunderbird (DSA 5034-1)
- 178986 Debian Security Update for thunderbird (DLA 2874-1)
- 182600 Debian Security Update for thunderbird (CVE-2021-4126)
- 198641 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5248-1)
- 198643 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5246-1)
- 376199 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2021-55)
- 502383 Alpine Linux Security Update for thunderbird
- 505450 Alpine Linux Security Update for thunderbird
- 751599 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2022:0058-1)