Thunderbird versions prior to 91.3.0 are vulnerable to...
Critical severity
Unreviewed
Published
Feb 17, 2023
to the GitHub Advisory Database
•
Updated Mar 8, 2023
Description
Published by the National Vulnerability Database
Feb 16, 2023
Published to the GitHub Advisory Database
Feb 17, 2023
Last updated
Mar 8, 2023
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
References