CVE-2021-29950: High severity thunderbird vulnerability
Published Mar 8, 2021
·Updated
Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state.
Affected Software
2 affected componentsFixes available
Mozilla Thunderbird<78.8.1
78.8.1
Mozilla Thunderbird<78.8.1
Event History
Mar 8, 2021
CVE Published
12:00 AM
Jun 24, 2021
CVE Published
via MITRE·01:18 PM
Data Sourced
via MITRE·01:18 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-29950?
CVE-2021-29950 is classified as a high severity vulnerability due to the risk of exposing secret OpenPGP keys.
2
How do I fix CVE-2021-29950?
To mitigate CVE-2021-29950, users should update Thunderbird to version 78.8.1 or later.
3
What impact does CVE-2021-29950 have on Thunderbird users?
CVE-2021-29950 may allow an attacker to access unprotected secret keys if a decryption or signing operation fails.
4
Is CVE-2021-29950 limited to specific Thunderbird versions?
Yes, CVE-2021-29950 affects versions of Thunderbird prior to 78.8.1.
5
What components of Thunderbird are affected by CVE-2021-29950?
CVE-2021-29950 affects the OpenPGP functionality used for encryption and signing tasks.