[MFSA-2021-19] Security Vulnerabilities fixed in Thunderbird 78.10.1

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1
  • CVE-2021-29951: Thunderbird Maintenance Service could have been started or stopped by domain users (moderate) The Maintenance Service granted SERVICE_START access to <code>BUILTIN|Users</code> which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. Note: This issue only affected Windows operating systems older than Win 10 build 1709. Other operating systems are unaffected.
Package Affected Version
pkg:mozilla/Thunderbird < 78.10.1
Package Fixed Version
pkg:mozilla/Thunderbird = 78.10.1
Source # ID Name URL
Bugzilla 1690062 https://bugzilla.mozilla.org/show_bug.cgi?id=1690062
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:mozilla/Thunderbird Thunderbird < 78.10.1
Fixed pkg:mozilla/Thunderbird Thunderbird = 78.10.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date