CVE-2018-18513: Null Pointer Dereference
A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-of-service (DOS) attack because Thunderbird reopens the last seen message on restart, triggering the crash again.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-18513?
CVE-2018-18513 is a vulnerability that can cause a crash when processing a crafted S/MIME message or an XPI package containing a crafted signature in Thunderbird.
How can CVE-2018-18513 be exploited?
CVE-2018-18513 can be exploited by sending a crafted S/MIME message or an XPI package with a crafted signature to a vulnerable version of Thunderbird, causing it to crash.
What is the severity of CVE-2018-18513?
CVE-2018-18513 has a severity rating of high with a CVSS score of 7.5.
Which versions of Thunderbird are affected by CVE-2018-18513?
Thunderbird versions prior to 60.5 are affected by CVE-2018-18513.
How do I fix CVE-2018-18513?
To fix CVE-2018-18513, update Thunderbird to version 60.5 or later.