CWE
312
Advisory Published
CVE Published
Updated

CVE-2021-29956

First published: Mon May 17 2021(Updated: )

OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master password protection was inactive for those keys. Version 78.10.2 will restore the protection mechanism for newly imported keys, and will automatically protect keys that had been imported using affected Thunderbird versions.

Credit: security@mozilla.org

Affected SoftwareAffected VersionHow to fix
Mozilla Thunderbird<78.10.2
78.10.2
<78.10.2
78.10.2
Mozilla Thunderbird>=78.8.1<=78.10.1

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Parent vulnerabilities

(Appears in the following advisories)

Peer vulnerabilities

(Found alongside the following vulnerabilities)

Frequently Asked Questions

  • What is the severity of CVE-2021-29956?

    The severity of CVE-2021-29956 is considered high due to the exposure of unencrypted OpenPGP secret keys.

  • How do I fix CVE-2021-29956?

    To fix CVE-2021-29956, update to Mozilla Thunderbird version 78.10.2 or later.

  • What are the risks associated with CVE-2021-29956?

    The risks of CVE-2021-29956 include unauthorized access to sensitive cryptographic keys stored unencrypted on local disks.

  • Who is affected by CVE-2021-29956?

    Users of Mozilla Thunderbird versions 78.8.1 through 78.10.1 who imported OpenPGP secret keys are affected by CVE-2021-29956.

  • What has changed in Thunderbird with the fix for CVE-2021-29956?

    The fix for CVE-2021-29956 re-enables the master password protection mechanism for newly imported OpenPGP keys.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203