First published: Mon May 17 2021(Updated: )
If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indicate that only parts of the message are protected.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <78.10.2 | 78.10.2 |
<78.10.2 | 78.10.2 | |
Mozilla Thunderbird | <78.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29957 has a moderate severity level due to the potential for user confusion regarding the protection of email message parts.
To fix CVE-2021-29957, update Mozilla Thunderbird to version 78.10.2 or later.
CVE-2021-29957 affects all versions of Mozilla Thunderbird prior to 78.10.2.
CVE-2021-29957 could expose users to the risk of unprotected message parts being misinterpreted as secure content.
CVE-2021-29957 specifically affects Mozilla Thunderbird and does not directly apply to other email clients.