SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-23992

An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID.

MEDIUM 4.3EPSS 0.48%

Does this matter?

Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.

Description

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to the correspondent. This vulnerability affects Thunderbird < 78.9.1.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS
0.48% probability · 40th percentile
CISA KEV
Not listed
Weakness
CWE-347
Affected
mozilla/thunderbird
Source
security@mozilla.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.