CVE-2021-29948: Race Condition
Published Apr 19, 2021
·Updated
Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file.
Affected Software
3 affected componentsFixes available
debian/thunderbird
1:91.12.0-1~deb10u11:115.3.1-1~deb10u11:102.13.1-1~deb11u11:115.3.1-1~deb11u11:102.15.1-1~deb12u11:115.3.1-1~deb12u11:115.3.1-1
Mozilla Thunderbird<78.10
78.10
Mozilla Thunderbird<78.10
Remediation
Patch Available
Event History
Apr 19, 2021
CVE Published
12:00 AM
Jun 24, 2021
CVE Published
via MITRE·01:19 PM
Data Sourced
via MITRE·01:19 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2021-29948?
CVE-2021-29948 has a moderate severity rating due to the potential for a race condition affecting signature verification.
2
What vulnerable software is affected by CVE-2021-29948?
CVE-2021-29948 affects Mozilla Thunderbird versions up to and including 78.10.
3
How do I fix CVE-2021-29948?
To fix CVE-2021-29948, upgrade Mozilla Thunderbird to a version later than 78.10.
4
What type of vulnerability is CVE-2021-29948?
CVE-2021-29948 is a race condition vulnerability related to signature file handling.
5
Can CVE-2021-29948 be exploited by local attackers?
Yes, CVE-2021-29948 can potentially be exploited by a malicious local process or user.