CVE-2021-23992: Medium severity thunderbird vulnerability
Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to the correspondent.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-23992?
The severity of CVE-2021-23992 is classified as moderate.
How do I fix CVE-2021-23992?
To fix CVE-2021-23992, update Thunderbird to version 78.9.1 or later.
What kind of attack does CVE-2021-23992 enable?
CVE-2021-23992 enables an attacker to craft a malicious OpenPGP key that may be incorrectly accepted by Thunderbird.
Which versions of Thunderbird are affected by CVE-2021-23992?
CVE-2021-23992 affects Thunderbird versions prior to 78.9.1.
Is there a workaround for CVE-2021-23992?
No specific workaround is available for CVE-2021-23992; the recommended action is to update to the patched version.