CVE-2018-12373Sensitive Information Exposure in Mozilla Thunderbird

Severity
6.5MEDIUMNVD
OSV8.8
EPSS
1.1%
top 21.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 18
Latest updateMay 13

Description

dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderbird < 52.9.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages7 packages

CVEListV5mozilla/thunderbirdunspecified52.9
NVDmozilla/thunderbird< 52.9.0
Debianmozilla/thunderbird< 1:52.9.0-1+3
Ubuntumozilla/thunderbird< 1:52.9.1+build3-0ubuntu0.14.04.1+2

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.10, 18.04, Enterprise Linux 6.0, 7.0, 7.5, 7.6

🔴Vulnerability Details

4
GHSA
GHSA-6x9p-vcwr-3q9w: dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward2022-05-13
OSV
CVE-2018-12373: dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward2018-10-18
CVEList
CVE-2018-12373: dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward2018-10-18
OSV
thunderbird vulnerabilities2018-07-12

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2018-07-12
Red Hat
thunderbird: S/MIME plaintext can be leaked through HTML reply/forward2018-05-27
Debian
CVE-2018-12373: thunderbird - dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plain...2018

💬Community

2
Bugzilla
CVE-2018-12373 thunderbird: S/MIME plaintext can be leaked through HTML reply/forward [fedora-all]2018-07-05
Bugzilla
CVE-2018-12373 thunderbird: S/MIME plaintext can be leaked through HTML reply/forward2018-07-05
CVE-2018-12373 — Sensitive Information Exposure | cvebase