CVE-2019-11755: High severity Mozilla Thunderbird vulnerability
A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message. Previous versions had only suppressed showing a digital signature for messages with an outer multipart/signed layer.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11755?
CVE-2019-11755 is a vulnerability in S/MIME where a crafted message with an encryption layer and a SignedData layer may show a valid digital signature despite the signer not having access to the encrypted message.
Which software is affected by CVE-2019-11755?
Mozilla Thunderbird versions up to 68.1.1 and some versions of Thunderbird in Debian and Ubuntu are affected.
What is the severity of CVE-2019-11755?
The severity of CVE-2019-11755 is high with a CVSS score of 7.5.
How can I fix CVE-2019-11755?
Update Mozilla Thunderbird to version 68.2.1 or later, or follow the recommended package updates for Debian and Ubuntu.
Where can I find more information about CVE-2019-11755?
You can find more information about CVE-2019-11755 in the references provided: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1240290), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2019-32/), [CVE Mitre](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11755).