Cleartext storage of sensitive information in Mozilla Thunderbird - CVE-2021-29950

 

Cleartext storage of sensitive information in Mozilla Thunderbird - CVE-2021-29950

Published: April 20, 2021


Vulnerability identifier: #VU52375
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29950
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to the way Thunderbird handles secret OpenPGP keys. The application unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. A local user or malicious application can read the key and use it to decrypt email messages.


Affected software

Mozilla Thunderbird
SUSE Linux Enterprise Workstation Extension
Ubuntu
thunderbird (Ubuntu package)
MozillaThunderbird
MozillaThunderbird-debuginfo
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other

How to mitigate CVE-2021-29950

Install updates from vendor's website.

Mozilla Thunderbird - update to 78.9.1
thunderbird (Ubuntu package) - addressed in versions 1:78.8.1+build1-0ubuntu0.20.04.1, 1:78.8.1+build1-0ubuntu0.20.10.1
MozillaThunderbird - update to 78.10.2-8.27.1
MozillaThunderbird-debuginfo - update to 78.10.2-8.27.1
MozillaThunderbird-debugsource - update to 78.10.2-8.27.1
MozillaThunderbird-translations-common - update to 78.10.2-8.27.1
MozillaThunderbird-translations-other - update to 78.10.2-8.27.1

External References

Related Security Bulletins