Cryptographic issues in Mozilla Thunderbird - CVE-2021-23991
Published: April 8, 2021
Mozilla Thunderbird
Mozilla
Description
The vulnerability allows a remote attacker to email encryption.
The vulnerability exists in the way Thunderbird uses the OpenPGP key refresh mechanism while handling the extended validity key period. A remote attacker can send victim an email containing a crafted version of the original key and an invalid subkey and force the application to use the invalid subkey, which will result in failure to encrypt the original email message when sending it.