Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.
2021-06-24T14:15:09.860
2024-11-21T06:02:02.413
Modified
CVSSv3.1: 2.5 (LOW)
AV:L/AC:M/Au:N/C:N/I:P/A:N
3.4
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | thunderbird | < 78.10 | Yes |