Thunderbird and Logjam

Revision Information
  • Revision id: 102951
  • Created:
  • Creator: Tonnes
  • Comment: Several nits. Line 1 may need rewording to clarify (and easier l10n)
  • Reviewed: Yes
  • Reviewed:
  • Reviewed by: jsavage
  • Is approved? Yes
  • Is current revision? No
  • Ready for localization: No
Revision Source
Revision Content

The release of Thunderbird 38.1 and the ESR release 31.8 saw the work done by the Firefox core developers to patch the LogJam common vulterability (CVE-2015-4000) in all Mozilla products using the Geko core engine ripple through to Thunderbird as a security and stability patch.

What does this mean to me?

Nothing, unless your mail server is still using very old cipher keys for SSL/TLS. If the server has not been patched to use a more recent set of keys (2048 bit), your connection to the server will fail with the following distinctive error message appearing in the Error console (Ctrl + Shift + J).

LogJam in the error console

What do I need to do?

  • If a mail server you use is affected, in the first instance contact your mail provider. All servers should be updated to protect you and your information.
  • If you are the mail server administrator, you need to view the info published by the Working Group that detected the issue here.
When visiting that page, your browser will be tested to see if it is vulnerable to the attack, and you will be notified accordingly.

There is a short-term workaround for those using Thunderbird, by installing the add-on Disable DHE. This add-on is listed in the add-ons site for Firefox, and therefore must be downloaded and installed into Thunderbird from the file downloaded ny Firefox or any other browser. It will not appear in the Thunderbird add-ons manager if you search for it from there.

The use of the add-on is not a long term solution, and is not a substitute for fixing the server. By using it, you are at risk of a man-in-the-middle attack, but it gives breathing time for the server adminstrator to generate and install better key pairs on the server.