#VU59081 Insufficient UI Warning of Dangerous Operations in Mozilla Thunderbird - CVE-2021-4126
Published: December 21, 2021
Mozilla Thunderbird
Mozilla
Description
The vulnerability allows a remote attacker to perform spoofing attacks.
The vulnerability exists in the way Thunderbird handles signed email messages. When receiving an OpenPGP/MIME signed email message that contains an additional outer MIME message layer, for example a message footer added by a mailing list gateway, Thunderbird only considered the inner signed message for the signature validity. This gave the false impression that the additional contents were also covered by the digital signature.