CVE-2021-29957

MEDIUM

Thunderbird < 78.10.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indicate that only parts of the message are protected. This vulnerability affects Thunderbird < 78.10.2.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://www.mozilla.org/security/advisories/mfsa2021-22/
Exploit, Patch, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=1673241

Scores

CVSS v3 4.3
EPSS 0.0031
EPSS Percentile 53.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

Status published
Products (1)
mozilla/thunderbird < 78.10.2
Published Jun 24, 2021
Tracked Since Feb 18, 2026