CVE-2018-18509
Summary
| CVE | CVE-2018-18509 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-26 17:29:00 UTC |
| Updated | 2019-06-03 19:29:00 UTC |
| Description | A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content. This vulnerability affects Thunderbird < 60.5.1. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [security-announce] openSUSE-SU-2019:1162-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| Johnny-You-Are-Fired/johnny-fired.pdf at master · RUB-NDS/Johnny-You-Are-Fired · GitHub |
MISC |
github.com |
|
| Security vulnerabilities fixed in Thunderbird 60.5.1 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| Access Denied |
MISC |
bugzilla.mozilla.org |
Issue Tracking, Permissions Required, Vendor Advisory |
| GitHub - RUB-NDS/Johnny-You-Are-Fired: Artifacts for the USENIX publication. |
MISC |
github.com |
|
| oss-security - Spoofing OpenPGP and S/MIME Signatures in Emails (multiple clients) |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| Johnny You Are Fired ≈ Packet Storm |
MISC |
packetstormsecurity.com |
Third Party Advisory, VDB Entry |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| Full Disclosure: OpenPGP and S/MIME signature forgery attacks in multiple email clients |
FULLDISC |
seclists.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710177 Gentoo Linux Mozilla Thunderbird and Firefox Multiple vulnerabilities (GLSA 201904-07)