QID 375485

Date Published: 2021-04-26

QID 375485: Mozilla Thunderbird Multiple Vulnerabilities (MFSA2021-14)

Thunderbird is a free and open-source web browser developed for Windows, OS X, and Linux, with a mobile version for Android.

Affected Products:
Prior to Mozilla Thunderbird 78.10

QID Detection Logic (Authenticated):
This checks for vulnerable version of Thunderbird browser.

An attacker may use Thunderbird's OpenPGP key refresh mechanism to poison an existing key

  • CVSS V3 rated as High - 7.4 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Vendor has released fix to address these vulnerabilities. Refer to MFSA2021-14
    Software Advisories
    Advisory ID Software Component Link
    mfsa2021-14 URL Logo www.mozilla.org/en-US/security/advisories/mfsa2021-14