CVE-2018-12372: Infoleak
A flaw was found in Mozilla Thunderbird before version 52.9. Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward.
References: https://www.mozilla.org/en-US/security/advisories/mfsa2018-18/#CVE-2018-12372
Other sources
Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 52.9.
— Launchpad
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2018-12372?
CVE-2018-12372 is classified as a moderate severity vulnerability.
How do I fix CVE-2018-12372?
To fix CVE-2018-12372, update Mozilla Thunderbird to version 52.9 or later.
What versions of Thunderbird are affected by CVE-2018-12372?
CVE-2018-12372 affects all versions of Mozilla Thunderbird prior to 52.9.
What is the impact of CVE-2018-12372?
CVE-2018-12372 can lead to the leakage of plaintext from decrypted S/MIME parts in crafted HTML messages.
Is CVE-2018-12372 present in Debian packages?
Yes, CVE-2018-12372 is present in Debian packages of Thunderbird before version 1:115.12.0-1~deb11u1.