UBUNTU-CVE-2021-38502

    Dashboard / Vulnerabilities / UBUNTU-CVE-2021-38502

    UBUNTU-CVE-2021-38502

    Published: 3 Nov 2021Last Modified: 22 Apr 2026
    Upstream:
    Aliases:

    Summary:

    Details: Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird < 91.2.

    Affected packages

    Package

    Name: thunderbird

    Purl: pkg:deb/ubuntu/thunderbird@1:91.5.0+build1-0ubuntu0.18.04.1?arch=source&distro=bionic

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1:91.5.0+build1-0ubuntu0.18.04.1

    Affected versions

    1:52.4.0+build1-0ubuntu2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    UBUNTU-CVE-2021-38502 | CVE-DB