CVE-2021-23991: Medium severity thunderbird vulnerability
If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-23991?
CVE-2021-23991 has been rated as a moderate severity vulnerability.
How can I fix CVE-2021-23991?
To fix CVE-2021-23991, update Mozilla Thunderbird to version 78.9.1 or later.
What does CVE-2021-23991 affect?
CVE-2021-23991 affects users of Mozilla Thunderbird versions prior to 78.9.1.
What type of attack does CVE-2021-23991 involve?
CVE-2021-23991 involves an attacker potentially sending a crafted email containing a malicious version of a user's OpenPGP key.
What should I do if I'm affected by CVE-2021-23991?
If you are affected by CVE-2021-23991, you should import the updated OpenPGP key and upgrade to the latest version of Thunderbird.