CVE-2021-38502: Medium severity thunderbird vulnerability
Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2021-38502?
CVE-2021-38502 is a vulnerability in Thunderbird where it ignored the configuration to require STARTTLS security for an SMTP connection, allowing for a MITM downgrade attack and interception of transmitted messages.
How does CVE-2021-38502 affect Thunderbird?
CVE-2021-38502 affects Thunderbird versions up to 91.2, allowing for a MITM downgrade attack on SMTP connections.
How does CVE-2021-38502 affect Debian Linux?
CVE-2021-38502 affects Debian Linux versions 9.0, 10.0, and 11.0, where Thunderbird versions up to 91.2 are vulnerable.
What is the severity of CVE-2021-38502?
CVE-2021-38502 has a high severity rating of 5.9.
How can I fix CVE-2021-38502 in Thunderbird?
To fix CVE-2021-38502 in Thunderbird, update to version 91.2 or later.