Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-43529


Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.


Published

2023-02-16T22:15:10.810

Last Modified

2025-03-19T15:15:36.897

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-787
  • Type: Secondary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mozilla thunderbird < 91.3.0 Yes

References