QID 198483

QID 198483: Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5058-1)

Thunderbird didn't ignore imap server responses prior to completion of the starttls handshake.
Multiple security issues were discovered in thunderbird

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

a person-in-the-middle could potentially exploit this to trick thunderbird into showing incorrect information. (
Cve-2021-29969).
If a user were tricked into opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, or execute arbitrary code. (
Cve-2021-29970, cve-2021-29976, cve-2021-29980, cve-2021-29984, cve-2021-29985, cve-2021-29986, cve-2021-29988, cve-2021-29989, cve-2021-30547)

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Refer to Ubuntu advisory: USN-5058-1 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-5058-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5058-1