Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-29948

Опубликовано: 19 апр. 2021
Источник: redhat
CVSS3: 2.5

Описание

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6thunderbirdOut of support scope
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2021:135026.04.2021
Red Hat Enterprise Linux 8thunderbirdFixedRHSA-2021:135326.04.2021
Red Hat Enterprise Linux 8.1 Extended Update SupportthunderbirdFixedRHSA-2021:135126.04.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportthunderbirdFixedRHSA-2021:135226.04.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=1951381Mozilla: Race condition when reading from disk while verifying signatures

2.5 Low

CVSS3

Связанные уязвимости

CVSS3: 2.5
ubuntu
около 4 лет назад

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.

CVSS3: 2.5
nvd
около 4 лет назад

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.

CVSS3: 2.5
debian
около 4 лет назад

Signatures are written to disk before and read during verification, wh ...

github
около 3 лет назад

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.

CVSS3: 7.8
fstec
больше 4 лет назад

Уязвимость почтового клиента Thunderbird, вызванная ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю обойти существующие ограничения безопасности

2.5 Low

CVSS3