#VU52003 Input validation error in Mozilla Thunderbird - CVE-2021-23993
Published: April 8, 2021
Mozilla Thunderbird
Mozilla
Description
The vulnerability allows a remote attacker to disable sending of encrypted messages.
The vulnerability exists due to insufficient validation of imported OpenPGP keys. A remote attacker can force the victim to import a specially crafted OpenPGO key with a subkey that has an invalid self signature and prevent users from sending encrypted messages to a correspondent.