CVE-2021-23992
Mozilla: A crafted OpenPGP key with an invalid user ID could be used to confuse the user
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to the correspondent. This vulnerability affects Thunderbird < 78.9.1.
Thunderbird no comprueba si el ID de usuario asociado a una clave OpenPGP presenta una autofirma válida. Un atacante puede crear una versión diseñada de una clave OpenPGP, sustituyendo el ID de usuario original o añadiendo otro ID de usuario. Si Thunderbird importa y acepta la clave diseñada, el usuario de Thunderbird puede concluir falsamente que el falso ID de usuario pertenece al corresponsal. Esta vulnerabilidad afecta a Thunderbird versiones anteriores a 78.9.1
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-13 CVE Reserved
- 2021-04-14 CVE Published
- 2024-03-09 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-347: Improper Verification of Cryptographic Signature
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.mozilla.org/security/advisories/mfsa2021-13 | 2021-07-08 | |
https://access.redhat.com/security/cve/CVE-2021-23992 | 2021-04-14 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1948394 | 2021-04-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | < 78.9.1 Search vendor "Mozilla" for product "Thunderbird" and version " < 78.9.1" | - |
Affected
|