CVE-2021-29969: Medium severity thunderbird vulnerability
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. This could have resulted in Thunderbird showing incorrect information, for example the attacker could have tricked Thunderbird to show folders that didn't exist on the IMAP server.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-29969?
CVE-2021-29969 has a moderate severity level due to the potential for attackers to inject misleading data.
How do I fix CVE-2021-29969?
To fix CVE-2021-29969, users should upgrade Thunderbird to version 78.12 or later.
What versions of Thunderbird are affected by CVE-2021-29969?
CVE-2021-29969 affects Thunderbird versions prior to 78.12.
What impact does CVE-2021-29969 have on Thunderbird users?
CVE-2021-29969 may cause Thunderbird to display incorrect information due to injected IMAP server responses.
Is there a workaround for CVE-2021-29969?
There is no specific workaround for CVE-2021-29969; users are advised to update Thunderbird to the latest version.