QID 198415

Date Published: 2021-06-28

QID 198415: Ubuntu Security Notification for Thunderbird vulnerabilities (USN-4995-1)

Multiple security issues were discovered in thunderbirdextensions could open popup windows with control of the window title in some circumstances.
multiple security issues were discovered in thunderbird's openpgp integration a use-after-free was discovered when responsive design mode was enabledthunderbird mishandled ftp urls with encoded newline characters.
Thunderbird wrote signatures to disk and read them back during verification.
Thunderbird might load an alternative otr library.
Secret keys imported into thunderbird were stored unencrypted.
Thunderbird did not indicate when an inline signed or encrypted message contained additional unprotected parts.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

if a user were tricked into opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, spoof the ui, bypass security restrictions, or execute arbitrary code. (
Cve-2021-23961, cve-2021-23981, cve-2021-23982, cve-2021-23987, cve-2021-23994, cve-2021-23998, cve-2021-23999, cve-2021-29945, cve-2021-29946, cve-2021-29967) if a user were tricked into installing a specially crafted extension, an attacker could potentially exploit this to spoof a website and trick the user into providing credentials. (
Cve-2021-23984).
If a user were tricked into importing a specially crafted key in some circumstances, an attacker could potentially exploit this to cause a denial of service (inability to send encrypted email) or confuse the user. (
Cve-2021-23991, cve-2021-23992, cve-2021-23993) if a user were tricked into opening a specially crafted website with responsive design mode enabled, an attacker could potentially exploit this to cause a denial of service, or execute arbitrary code. (
Cve-2021-23995) if a user were tricked into clicking on a specially crafted link, an attacker could potentially exploit this to send arbitrary ftp commands. (
Cve-2021-24002).
A local attacker could potentially exploit this to replace the data with another signature file. (
Cve-2021-29948).
If a user were tricked into copying a specially crafted library to one of thunderbird's search paths, an attacker could potentially exploit this to execute arbitrary code. (
Cve-2021-29949).
A local attacker could potentially exploit this to obtain private keys. (
Cve-2021-29956).
(cve-2021-29957).

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Refer to Ubuntu advisory: USN-4995-1 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-4995-1 Ubuntu Linux URL Logo usn.ubuntu.com/4995-1