Unprotected Part Disclosure in Thunderbird MIME Encoded Email

Unprotected Part Disclosure in Thunderbird MIME Encoded Email

CVE-2021-29957 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indicate that only parts of the message are protected. This vulnerability affects Thunderbird < 78.10.2.

Learn more about our Web Application Penetration Testing UK.