[MFSA-2021-17] Security Vulnerabilities fixed in Thunderbird 78.8.1
Severity
Moderate
Affected Packages
1
Fixed Packages
1
CVEs
1
Note: This advisory was issued April 20, 2021 to include CVE-2021-29950.
- CVE-2021-29950: Logic issue potentially leaves key material unlocked (moderate) Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state.
Package | Affected Version |
---|---|
pkg:mozilla/Thunderbird | < 78.8.1 |
Package | Fixed Version |
---|---|
pkg:mozilla/Thunderbird | = 78.8.1 |
- ID
- MFSA-2021-17
- Severity
- moderate
- URL
- https://www.mozilla.org/en-US/security/advisories/mfsa2021-17
- Published
-
2021-03-08T00:00:00
(3 years ago) - Modified
-
2021-03-08T00:00:00
(3 years ago) - Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 1673239 | https://bugzilla.mozilla.org/show_bug.cgi?id=1673239 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:mozilla/Thunderbird | Thunderbird | < 78.8.1 | ||||
Fixed | pkg:mozilla/Thunderbird | Thunderbird | = 78.8.1 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |