PublicDateAtUSN: 2021-04-22 14:54:00 UTC Candidate: CVE-2021-29948 PublicDate: 2021-06-24 14:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29948 https://www.mozilla.org/en-US/security/advisories/mfsa2021-14/#CVE-2021-29948 https://access.redhat.com/security/cve/CVE-2021-29948 https://ubuntu.com/security/notices/USN-4995-1 https://ubuntu.com/security/notices/USN-4995-2 Description: Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N [2.5 LOW] Patches_thunderbird: upstream_thunderbird: released (78.10) precise/esm_thunderbird: DNE trusty_thunderbird: ignored (out of standard support) trusty/esm_thunderbird: DNE xenial_thunderbird: ignored (end of standard support, was needs-triage) esm-infra/xenial_thunderbird: needs-triage bionic_thunderbird: released (1:78.11.0+build1-0ubuntu0.18.04.2) focal_thunderbird: released (1:78.11.0+build1-0ubuntu0.20.04.2) groovy_thunderbird: released (1:78.11.0+build1-0ubuntu0.20.10.2) hirsute_thunderbird: released (1:78.11.0+build1-0ubuntu0.21.04.2) impish_thunderbird: released (1:78.11.0+build1-0ubuntu2) jammy_thunderbird: released (1:78.11.0+build1-0ubuntu2) devel_thunderbird: released (1:78.11.0+build1-0ubuntu2)