CVE-2021-38510: High severity thunderbird vulnerability
The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.
Other sources
The executable file warning was not presented when downloading .inetloc files, which can run commands on a user's computer.Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.
— Mozilla
The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-38510.
What is the title of the vulnerability?
The title of the vulnerability is 'The executable file warning was not presented when downloading .inetloc files which can run commands...'
What is the affected software?
The affected software includes Mozilla Firefox ESR version up to 91.3, Mozilla Firefox version up to 94, and Mozilla Thunderbird version up to 91.3.
What is the severity of CVE-2021-38510?
The severity of CVE-2021-38510 is medium (severity value: 4).
How can I fix CVE-2021-38510?
To fix CVE-2021-38510, users should update their Mozilla Firefox ESR version to 91.3, Mozilla Firefox version to 94, or Mozilla Thunderbird version to 91.3.