PublicDateAtUSN: 2021-04-22 14:54:00 UTC Candidate: CVE-2021-29949 PublicDate: 2021-06-24 14:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29949 https://www.mozilla.org/en-US/security/advisories/mfsa2021-13/#CVE-2021-29949 https://access.redhat.com/security/cve/CVE-2021-29949 https://ubuntu.com/security/notices/USN-4995-1 https://ubuntu.com/security/notices/USN-4995-2 Description: When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distributed by Thunderbird. If a computer has already been infected with a malicious library of the alternative filename, and the malicious library has been copied to a directory that is contained in the search path for executable libraries, then Thunderbird will load the incorrect library. This vulnerability affects Thunderbird < 78.9.1. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_thunderbird: upstream_thunderbird: released (78.9.1) precise/esm_thunderbird: DNE trusty_thunderbird: ignored (out of standard support) trusty/esm_thunderbird: DNE xenial_thunderbird: ignored (end of standard support, was needs-triage) esm-infra/xenial_thunderbird: needs-triage bionic_thunderbird: released (1:78.11.0+build1-0ubuntu0.18.04.2) focal_thunderbird: released (1:78.11.0+build1-0ubuntu0.20.04.2) groovy_thunderbird: released (1:78.11.0+build1-0ubuntu0.20.10.2) hirsute_thunderbird: released (1:78.11.0+build1-0ubuntu0.21.04.2) impish_thunderbird: released (1:78.11.0+build1-0ubuntu2) jammy_thunderbird: released (1:78.11.0+build1-0ubuntu2) devel_thunderbird: released (1:78.11.0+build1-0ubuntu2)