CVE-2021-29949
Dashboard / Vulnerabilities / CVE-2021-29949
CVE-2021-29949
Published: 24 Jun 2021Last Modified: 14 Mar 2026
Summary:
Details: When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distributed by Thunderbird. If a computer has already been infected with a malicious library of the alternative filename, and the malicious library has been copied to a directory that is contained in the search path for executable libraries, then Thunderbird will load the incorrect library. This vulnerability affects Thunderbird < 78.9.1.
References: https://www.mozilla.org/security/advisories/mfsa2021-13/, https://bugzilla.mozilla.org/show_bug.cgi?id=1682101
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
