QID 375959
Date Published: 2021-10-20
QID 375959: Mozilla Thunderbird Multiple Vulnerabilities (MFSA2021-47)
Thunderbird is a free and open-source cross-platform email client developed for Windows, OS X, and Linux, with a mobile version for Android.
Mozilla Firefox is prone to
CVE-2021-38502 Downgrade attack on SMTP STARTTLS connections
CVE-2021-38496 Use-after-free in MessageTask
CVE-2021-38497 Validation message could have been overlaid on another origin
CVE-2021-38498 Use-after-free of nsLanguageAtomService object
CVE-2021-32810 Data race in crossbeam-deque
CVE-2021-38500 Memory safety bugs
CVE-2021-38501 Memory safety bugs
Affected Products:
Prior to Mozilla Thunderbird 91.2
Successful exploitation of this vulnerability may allow an attacker to corrupt memory leading to a potentially exploitable crash.
Solution
Vendor has released fix to address these vulnerabilities. Refer to MFSA2021-47
Vendor References
- MFSA2021-47 -
www.mozilla.org/en-US/security/advisories/mfsa2021-47/
CVEs related to QID 375959
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| MFSA2021-47 |
|