First published: Tue Jan 29 2019(Updated: )
A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-of-service (DOS) attack because Thunderbird reopens the last seen message on restart, triggering the crash again.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <60.5 | 60.5 |
<60.5 | 60.5 | |
Mozilla Thunderbird | <60.5.0 | |
debian/thunderbird | 1:91.12.0-1~deb10u1 1:115.6.0-1~deb10u1 1:102.13.1-1~deb11u1 1:115.6.0-1~deb11u1 1:115.5.0-1~deb12u1 1:115.6.0-1~deb12u1 1:115.6.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-18513 is a vulnerability that can cause a crash when processing a crafted S/MIME message or an XPI package containing a crafted signature in Thunderbird.
CVE-2018-18513 can be exploited by sending a crafted S/MIME message or an XPI package with a crafted signature to a vulnerable version of Thunderbird, causing it to crash.
CVE-2018-18513 has a severity rating of high with a CVSS score of 7.5.
Thunderbird versions prior to 60.5 are affected by CVE-2018-18513.
To fix CVE-2018-18513, update Thunderbird to version 60.5 or later.