Oval Definition:oval:org.opensuse.security:def:202123992
Revision Date:2022-09-02Version:1
Title:CVE-2021-23992
Description:

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to the correspondent. This vulnerability affects Thunderbird < 78.9.1.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2021-23992
SUSE CVE-2021-23992
SUSE-SU-2021:1167-1
openSUSE-SU-2021:0580-1
Platform(s):openSUSE Leap 15.2
openSUSE Leap 15.3 SLE Imports
SUSE Linux Enterprise Desktop 15 SP2
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Workstation Extension 15 SP2
Product(s):
Definition Synopsis
  • openSUSE Leap 15.3 SLE Imports is installed
  • AND Package Information
  • MozillaThunderbird-78.9.1-8.20.1 is installed
  • AND MozillaThunderbird is signed with openSUSE key
  • OR
  • MozillaThunderbird-translations-common-78.9.1-8.20.1 is installed
  • AND MozillaThunderbird-translations-common is signed with openSUSE key
  • OR
  • MozillaThunderbird-translations-other-78.9.1-8.20.1 is installed
  • AND MozillaThunderbird-translations-other is signed with openSUSE key
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • MozillaThunderbird-78.9.1-lp152.2.38.1 is installed
  • AND MozillaThunderbird is signed with openSUSE key
  • OR
  • MozillaThunderbird-translations-common-78.9.1-lp152.2.38.1 is installed
  • AND MozillaThunderbird-translations-common is signed with openSUSE key
  • OR
  • MozillaThunderbird-translations-other-78.9.1-lp152.2.38.1 is installed
  • AND MozillaThunderbird-translations-other is signed with openSUSE key
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP2 is installed
  • OR SUSE Linux Enterprise Server 15 SP2 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
  • OR SUSE Linux Enterprise Workstation Extension 15 SP2 is installed
  • AND Package Information
  • MozillaThunderbird-78.9.1-8.20.1 is installed
  • OR MozillaThunderbird-translations-common-78.9.1-8.20.1 is installed
  • OR MozillaThunderbird-translations-other-78.9.1-8.20.1 is installed
  • BACK