VYPR
High severity7.8NVD Advisory· Published Jun 24, 2021· Updated Jun 17, 2026

CVE-2021-29949

CVE-2021-29949

Description

When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distributed by Thunderbird. If a computer has already been infected with a malicious library of the alternative filename, and the malicious library has been copied to a directory that is contained in the search path for executable libraries, then Thunderbird will load the incorrect library. This vulnerability affects Thunderbird < 78.9.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*range: <78.9.1
    • (no CPE)range: <78.9.1
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.