CVE-2021-29957: Medium severity thunderbird vulnerability
Published May 17, 2021
·Updated
If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indicate that only parts of the message are protected.
Affected Software
2 affected componentsFixes available
Mozilla Thunderbird<78.10.2
78.10.2
Mozilla Thunderbird<78.10.2
Remediation
Patch Available
Event History
May 17, 2021
CVE Published
12:00 AM
Jun 24, 2021
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-29957?
CVE-2021-29957 has a moderate severity level due to the potential for user confusion regarding the protection of email message parts.
2
How do I fix CVE-2021-29957?
To fix CVE-2021-29957, update Mozilla Thunderbird to version 78.10.2 or later.
3
What versions of Thunderbird are affected by CVE-2021-29957?
CVE-2021-29957 affects all versions of Mozilla Thunderbird prior to 78.10.2.
4
What types of attacks does CVE-2021-29957 expose users to?
CVE-2021-29957 could expose users to the risk of unprotected message parts being misinterpreted as secure content.
5
Can CVE-2021-29957 affect other email clients?
CVE-2021-29957 specifically affects Mozilla Thunderbird and does not directly apply to other email clients.