CVE-2018-18509: Medium severity Mozilla Thunderbird vulnerability
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 60.5.1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:140.12.0esr-1~deb11u1Fixed in 1:140.10.1esr-1~deb12u1Fixed in 1:140.11.0esr-1~deb12u1Fixed in 1:140.10.1esr-1~deb13u1Fixed in 1:140.11.0esr-1~deb13u1Fixed in 1:140.11.0esr-1Fixed in 1:140.12.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.12.0esr-1~deb11u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.10.1esr-1~deb12u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.11.0esr-1~deb12u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.10.1esr-1~deb13u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.11.0esr-1~deb13u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.11.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.12.0esr-1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-18509?
CVE-2018-18509 is a vulnerability in Thunderbird that allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary contents.
How does CVE-2018-18509 impact Thunderbird?
CVE-2018-18509 causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature.
What is the severity of CVE-2018-18509?
The severity of CVE-2018-18509 is high, with a CVSS (Common Vulnerability Scoring System) score of 5.3.
How can I fix CVE-2018-18509 in Thunderbird?
To fix CVE-2018-18509 in Thunderbird, you should update Thunderbird to version 60.5.1 or later.
Where can I find more information about CVE-2018-18509?
You can find more information about CVE-2018-18509 in the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1507218), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2019-06/), [Full Disclosure Mailing List](http://seclists.org/fulldisclosure/2019/Apr/38)