CVE-2021-29969 Details
Description
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. This could have resulted in Thunderbird showing incorrect information, for example the attacker could have tricked Thunderbird to show folders that didn't exist on the IMAP server. This vulnerability affects Thunderbird < 78.12.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=1682370 | CVE | Issue TrackingPermissions RequiredVendor Advisory |
| https://security.gentoo.org/glsa/202208-14 | CVE | Third Party Advisory |
| https://www.mozilla.org/security/advisories/mfsa2021-30/ | CVE | Vendor Advisory |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1682370 | [email protected] | Issue TrackingPermissions RequiredVendor Advisory |
| https://security.gentoo.org/glsa/202208-14 | [email protected] | Third Party Advisory |
| https://www.mozilla.org/security/advisories/mfsa2021-30/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-552 | Files or Directories Accessible to External Parties | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mozilla thunderbird | < 78.12 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 9, 2022 | Modified Analysis | [email protected] |
| Aug 10, 2022 | CVE Modified | [email protected] |
| Aug 12, 2021 | Initial Analysis | [email protected] |