If, say, Thunderbird is configured to use STARTTLS to talk to the IMAP and SMTP servers, can this attack strip it or will Thunderbird refuse to connect to an unencrypted server?
In very old versions of Thunderbird (pre-mercurial), there was an option akin to "TLS, if available" which would be vulnerable. But Thunderbird has not offered it as an option for new accounts for quite some time.