Bugzilla – Bug 1186199
VUL-1: CVE-2021-29956: MozillaThunderbird: Thunderbird stored OpenPGP secret keys without master password protection
Last modified: 2021-08-09 12:31:53 UTC
CVE-2021-29956 OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master password protection was inactive for those keys. Version 78.10.2 will restore the protection mechanism for newly imported keys, and will automatically protect keys that had been imported using affected Thunderbird versions. External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2021-22/#CVE-2021-29956 References: https://bugzilla.redhat.com/show_bug.cgi?id=1961504 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-29956
Affected packages: - SUSE:SLE-15-SP2:Update/MozillaThunderbird 78.10.0 - openSUSE:Factory/MozillaThunderbird 78.10.1 Please update to version >= 78.10.2
*** Bug 1186464 has been marked as a duplicate of this bug. ***
This is an autogenerated message for OBS integration: This bug (1186199) was mentioned in https://build.opensuse.org/request/show/897289 Factory / MozillaThunderbird
SUSE-SU-2021:1854-1: An update that fixes four vulnerabilities is now available. Category: security (moderate) Bug References: 1185086,1185633,1186198,1186199 CVE References: CVE-2021-29950,CVE-2021-29951,CVE-2021-29956,CVE-2021-29957 JIRA References: Sources used: SUSE Linux Enterprise Workstation Extension 15-SP3 (src): MozillaThunderbird-78.10.2-8.27.1 SUSE Linux Enterprise Workstation Extension 15-SP2 (src): MozillaThunderbird-78.10.2-8.27.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:1854-1: An update that fixes four vulnerabilities is now available. Category: security (moderate) Bug References: 1185086,1185633,1186198,1186199 CVE References: CVE-2021-29950,CVE-2021-29951,CVE-2021-29956,CVE-2021-29957 JIRA References: Sources used: openSUSE Leap 15.3 (src): MozillaThunderbird-78.10.2-8.27.1
done