CVE-2021-43541: Medium severity thunderbird vulnerability
Published Dec 7, 2021
·Updated
When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped.
Affected Software
12 affected componentsFixes available
debian/firefox
118.0.2-1
debian/firefox-esr
91.12.0esr-1~deb10u1115.3.1esr-1~deb10u1102.15.0esr-1~deb11u1115.3.1esr-1~deb11u1102.15.1esr-1~deb12u1115.3.0esr-1~deb12u1115.3.0esr-1115.4.0esr-1
debian/thunderbird
1:91.12.0-1~deb10u11:115.3.1-1~deb10u11:102.13.1-1~deb11u11:115.3.1-1~deb11u11:102.15.1-1~deb12u11:115.3.1-1~deb12u11:115.3.1-1
Mozilla Thunderbird<91.4
91.4
Mozilla Firefox<95
95
Mozilla Firefox ESR<91.4
91.4
Mozilla Firefox<95.0
Mozilla Firefox ESR<91.4.0
Mozilla Thunderbird<91.4.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Event History
Dec 7, 2021
CVE Published
12:00 AM
Dec 8, 2021
CVE Published
via MITRE·09:20 PM
Data Sourced
via MITRE·09:20 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2021-43541?
CVE-2021-43541 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2021-43541?
To fix CVE-2021-43541, update your Thunderbird or Firefox version to 91.4.0 or later.
3
What products are affected by CVE-2021-43541?
CVE-2021-43541 affects Thunderbird versions prior to 91.4.0 and certain versions of Firefox and Firefox ESR.
4
What kind of vulnerability is CVE-2021-43541?
CVE-2021-43541 is a URL handling vulnerability that fails to properly escape parameters in external protocol handlers.
5
Is CVE-2021-43541 exploitable remotely?
Yes, CVE-2021-43541 can be exploited remotely through crafted URLs that leverage the vulnerability.