CVE-2021-43529

CVSS V2 None CVSS V3 None
Description
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
Overview
  • CVE ID
  • CVE-2021-43529
  • Assigner
  • security@mozilla.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-02-16T22:15:10
  • Last Modified Date
  • 2023-02-28T13:55:26
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 1 OR 91.3.0
References
Reference URL Reference Tags
https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2021-43529 Issue Tracking
History
Created Old Value New Value Data Type Notes
2023-04-17 07:55:06 Added to TrackCVE
2023-04-17 07:55:07 Weakness Enumeration new