First published: Mon Dec 06 2021(Updated: )
Mozilla Thunderbird is a standalone mail and newsgroup client.<br>Security Fix(es):<br><li> nss: Memory corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS) (CVE-2021-43527)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/thunderbird | <91.3.0-3.el8_2 | 91.3.0-3.el8_2 |
redhat/thunderbird | <91.3.0-3.el8_2 | 91.3.0-3.el8_2 |
redhat/thunderbird-debuginfo | <91.3.0-3.el8_2 | 91.3.0-3.el8_2 |
redhat/thunderbird-debugsource | <91.3.0-3.el8_2 | 91.3.0-3.el8_2 |
redhat/thunderbird | <91.3.0-3.el8_2 | 91.3.0-3.el8_2 |
redhat/thunderbird-debuginfo | <91.3.0-3.el8_2 | 91.3.0-3.el8_2 |
redhat/thunderbird-debugsource | <91.3.0-3.el8_2 | 91.3.0-3.el8_2 |
redhat/thunderbird | <91.3.0-3.el8_2.aa | 91.3.0-3.el8_2.aa |
redhat/thunderbird-debuginfo | <91.3.0-3.el8_2.aa | 91.3.0-3.el8_2.aa |
redhat/thunderbird-debugsource | <91.3.0-3.el8_2.aa | 91.3.0-3.el8_2.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability RHSA-2021:4954 is classified as critical.
To fix RHSA-2021:4954, update to version 91.3.0-3.el8_2 of the Thunderbird package.
RHSA-2021:4954 affects the Thunderbird mail client and its associated debuginfo packages.
RHSA-2021:4954 addresses a memory corruption vulnerability in the decoding of DSA signatures.
The CVE associated with RHSA-2021:4954 is CVE-2021-43527.