QID 375825

Date Published: 2021-08-25

QID 375825: Mozilla Thunderbird Header Splitting Vulnerability(MFSA2021-37)

Thunderbird is a free and open-source cross-platform email client developed for Windows, OS X, and Linux, with a mobile version for Android.

Affected Products:
Prior to Mozilla Thunderbird 91.0.1

QID Detection Logic (Authenticated):
This checks for vulnerable version of Thunderbird.

This allowed for a header splitting attack against servers using HTTP/3.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Vendor has released fix to address these vulnerabilities. Refer to MFSA2021-37

    CVEs related to QID 375825

    Software Advisories
    Advisory ID Software Component Link
    MFSA2021-37 URL Logo www.mozilla.org/en-US/security/advisories/mfsa2021-37/