QID 375958

Date Published: 2021-10-19

QID 375958: Mozilla Thunderbird Multiple Vulnerabilities (MFSA2021-46)

Thunderbird is a free and open-source cross-platform email client developed for Windows, OS X, and Linux, with a mobile version for Android.

Mozilla Firefox is prone to
CVE-2021-38496: Use-after-free in MessageTask
CVE-2021-38500: Memory safety bugs

Affected Products:
Prior to Mozilla Thunderbird 78.15

QID Detection Logic (Authenticated):
This checks for vulnerable version of Thunderbird.

Successful exploitation of this vulnerability may allow an attacker to corrupt memory leading to a potentially exploitable crash.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Vendor has released fix to address these vulnerabilities. Refer to MFSA2021-46

    CVEs related to QID 375958

    Software Advisories
    Advisory ID Software Component Link
    MFSA2021-46 URL Logo www.mozilla.org/en-US/security/advisories/mfsa2021-46/