CVE-2018-12372Sensitive Information Exposure in Mozilla Thunderbird

Severity
6.5MEDIUMNVD
OSV8.8
EPSS
0.8%
top 26.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 18
Latest updateMay 13

Description

Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 52.9.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages7 packages

CVEListV5mozilla/thunderbirdunspecified52.9
NVDmozilla/thunderbird< 52.9.0
Debianmozilla/thunderbird< 1:52.9.0-1+3
Ubuntumozilla/thunderbird< 1:52.9.1+build3-0ubuntu0.14.04.1+2

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.10, 18.04, Enterprise Linux 6.0, 7.0, 7.5, 7.6

🔴Vulnerability Details

4
GHSA
GHSA-gfx4-4m6p-57vj: Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward2022-05-13
OSV
CVE-2018-12372: Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward2018-10-18
CVEList
CVE-2018-12372: Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward2018-10-18
OSV
thunderbird vulnerabilities2018-07-12

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2018-07-12
Red Hat
thunderbird: S/MIME and PGP decryption oracles can be built with HTML emails2018-07-04
Debian
CVE-2018-12372: thunderbird - Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak pl...2018

💬Community

2
Bugzilla
CVE-2018-12372 thunderbird: S/MIME and PGP decryption oracles can be built with HTML emails2018-07-05
Bugzilla
CVE-2018-12372 thunderbird: S/MIME and PGP decryption oracles can be built with HTML emails [fedora-all]2018-07-05
CVE-2018-12372 — Sensitive Information Exposure | cvebase