{"schema_version":"1.7.3","id":"SUSE-SU-2021:1854-1","published":"2021-06-04T06:54:13Z","modified":"2026-02-04T04:34:42.697343Z","related":["CVE-2021-29950","CVE-2021-29951","CVE-2021-29956","CVE-2021-29957"],"upstream":["CVE-2021-29950","CVE-2021-29951","CVE-2021-29956","CVE-2021-29957"],"summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n\n- Mozilla Thunderbird 78.10.2\n- CVE-2021-29957: Fixed partial protection of inline OpenPGP message not indicated (bsc#1186198).\n- CVE-2021-29956: Fixed Thunderbird stored OpenPGP secret keys without master password protection (bsc#1186199).\n- CVE-2021-29951: Fixed Thunderbird Maintenance Service could have been started or stopped by domain users (bsc#1185633).\n- CVE-2021-29950: Fixed logic issue potentially leaves key material unlocked (bsc#1185086).\n","affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP2","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"78.10.2-8.27.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"78.10.2-8.27.1","MozillaThunderbird-translations-common":"78.10.2-8.27.1","MozillaThunderbird-translations-other":"78.10.2-8.27.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:1854-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP3","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"78.10.2-8.27.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"78.10.2-8.27.1","MozillaThunderbird-translations-common":"78.10.2-8.27.1","MozillaThunderbird-translations-other":"78.10.2-8.27.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:1854-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2021/suse-su-20211854-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185086"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185633"},{"type":"REPORT","url":"https://bugzilla.suse.com/1186198"},{"type":"REPORT","url":"https://bugzilla.suse.com/1186199"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-29950"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-29951"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-29956"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-29957"}]}