Bug 2088353 (CVE-2021-43529)

Summary: CVE-2021-43529 thunderbird: Memory corruption when processing S/MIME messages
Product: [Other] Security Response Reporter: Mauro Matteo Cascella <mcascell>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: urgent Docs Contact:
Priority: urgent    
Version: unspecifiedCC: erack, jhorak, nobody, stransky, tpopela
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: thunderbird 91.3.0 Doc Type: ---
Doc Text:
A flaw was found in Thunderbird, which is vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-05-19 14:37:10 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2019254, 2019255, 2019256, 2019257    
Bug Blocks: 2078444    

Description Mauro Matteo Cascella 2022-05-19 09:38:15 UTC
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures. For more details about the original security issue, please refer to the Security Bulletin: https://access.redhat.com/security/vulnerabilities/RHSB-2021-008.

Upstream Thunderbird bug:
https://bugzilla.mozilla.org/show_bug.cgi?id=1738501

Comment 1 Product Security DevOps Team 2022-05-19 14:37:09 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-43529

Comment 2 Mauro Matteo Cascella 2022-05-23 13:22:25 UTC
Thunderbird upstream states that this issue was fixed in Thunderbird version 91.3.0. The thunderbird packages as shipped in Red Hat Enterprise Linux were previously updated to version 91.3.0 via the following errata:

thunderbird in Red Hat Enterprise Linux 7:
https://access.redhat.com/errata/RHSA-2021:4134

thunderbird in Red Hat Enterprise Linux 8.1 Extended Update Support:
https://access.redhat.com/errata/RHSA-2021:4133

thunderbird in Red Hat Enterprise Linux 8.2 Extended Update Support
https://access.redhat.com/errata/RHSA-2021:4132

thunderbird in Red Hat Enterprise Linux 8:
https://access.redhat.com/errata/RHSA-2021:4130