Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Mageia: 2021-0189 Moderate: OpenSSH Remote Access Vulnerability

mageia
Calendar Grey April 15, 2021
Dist Mageia Esm H88
Latest Thunderbird releases address significant vulnerabilities affecting password safeguarding and secure communication protocols.
An attacker may use Thunderbird's OpenPGP key refresh mechanism to poison an existing key (CVE-2021-23991)

Summary

An attacker may use Thunderbird's OpenPGP key refresh mechanism to poison an existing key (CVE-2021-23991).
A crafted OpenPGP key with an invalid user ID could be used to confuse the user (MOZ-2021-23992).
Inability to send encrypted OpenPGP email after importing a crafted OpenPGP key (CVE-2021-23993).

References

- https://bugs.mageia.org/show_bug.cgi?id=28764

- https://www.mozilla.org/en-US/security/advisories/mfsa2021-13/

- https://www.thunderbird.net/en-US/thunderbird/78.9.1/releasenotes/

- https://www.cve.org/CVERecord?id=CVE-2021-23991

- https://www.cve.org/CVERecord?id=CVE-2021-23993

Resolution

SRPMS

- 7/core/thunderbird-78.9.1-1.mga7

- 7/core/thunderbird-l10n-78.9.1-1.mga7

- 8/core/thunderbird-78.9.1-1.mga8

- 8/core/thunderbird-l10n-78.9.1-1.mga8

Publication date: 15 Apr 2021
URL: https://advisories.mageia.org/MGASA-2021-0189.html
Type: security
CVE: CVE-2021-23991, CVE-2021-23993

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here