Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2021-06-24T13:19:32

Updated: 2024-08-03T22:18:03.284Z

Reserved: 2021-04-01T00:00:00

Link: CVE-2021-29948

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-06-24T14:15:09.860

Modified: 2021-06-30T18:28:55.147

Link: CVE-2021-29948

cve-icon Redhat

Severity : Low

Publid Date: 2021-04-19T00:00:00Z

Links: CVE-2021-29948 - Bugzilla