Advisories ยป MGASA-2021-0189

Updated thunderbird packages fix security vulnerabilities

Publication date: 15 Apr 2021
Modification date: 26 Oct 2022
Type: security
Affected Mageia releases : 7 , 8
CVE: CVE-2021-23991 , CVE-2021-23992 , CVE-2021-23993

Description

An attacker may use Thunderbird's OpenPGP key refresh mechanism to poison an
existing key (CVE-2021-23991).

A crafted OpenPGP key with an invalid user ID could be used to confuse the
user (CVE-2021-23992).

Inability to send encrypted OpenPGP email after importing a crafted OpenPGP
key (CVE-2021-23993).
                

References

SRPMS

7/core

8/core