QID 198641

Date Published: 2022-01-24

QID 198641: Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5248-1)

Thunderbird ignored the configuration to requirestarttls for an smtp connection.
Javascript was unexpectedly enabled in thecomposition area.
Thunderbird's openpgp integration only consideredthe inner signed message when checking signature validity in a messagethat contains an additional outer mime layer.

Multiple security issues were discovered in thunderbird.
If a user weretricked into opening a specially crafted website in a browsing context, anattacker could potentially exploit these to cause a denial of service,obtain sensitive information, trick a user into accepting unwantedpermissions, conduct header splitting attacks, conduct spoofing attacks,bypass security restrictions, confuse the user, or execute arbitrary code.
A person-in-the-middle could potentiallyexploit this to perform a downgrade attack in order to intercept messagesor take control of a session.
An attacker could potentially exploit this incombination with another vulnerability, with unspecified impacts.
(cve-2021-43528)a buffer overflow was discovered in the matrix chat library bundled withthunderbird.
An attacker could potentially exploit this to cause a denialof service, or execute arbitrary code.
An attacker couldpotentially exploit this to trick the user into thinking that a messagehas a valid signature.

  • CVSS V3 rated as Critical - 10 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5248-1 for updates and patch information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-5248-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5248-1