CVE-2018-18509

MEDIUM

Thunderbird < 60.5.1 - Improper Verification of Cryptographic Signature

Title source: llm
STIX 2.1

Description

A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content. This vulnerability affects Thunderbird < 60.5.1.

References (9)

Core 9
Core References
Issue Tracking, Permissions Required, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=1507218
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/04/30/4
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/Apr/38
Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.html
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:1144

Scores

CVSS v3 5.3
EPSS 0.0025
EPSS Percentile 48.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-347
Status published
Products (1)
mozilla/thunderbird < 60.5.1
Published Apr 26, 2019
Tracked Since Feb 18, 2026