CVE-2018-18509
published 2019-04-26CVE-2018-18509: A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message…
PriorityP429medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
1.68%
74.5th percentile
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content. This vulnerability affects Thunderbird < 60.5.1.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:60.5.1-1 (bookworm) | thunderbird 1:60.5.1-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.4.0-165.193 | 4.4.0-165.193 |
| mozilla | thunderbird | < 60.5.1 | 60.5.1 |
| mozilla | thunderbird | >= 0 < 1:60.5.1-1 | 1:60.5.1-1 |
| mozilla | thunderbird | >= 0 < 1:60.5.1-1 | 1:60.5.1-1 |
| mozilla | thunderbird | >= 0 < 1:60.5.1-1 | 1:60.5.1-1 |
| mozilla | thunderbird | >= 0 < 1:60.5.1-1 | 1:60.5.1-1 |
| mozilla | thunderbird | >= 0 < 1:60.5.1+build2-0ubuntu0.14.04.1 | 1:60.5.1+build2-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:60.5.1+build2-0ubuntu0.16.04.1 | 1:60.5.1+build2-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= 0 < 1:60.5.1+build2-0ubuntu0.18.04.1 | 1:60.5.1+build2-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= unspecified < 60.5.1 | 60.5.1 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.8HIGH
vendor_ubuntu5.5MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pqr9-248w-h9pf: A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the show
ghsa_unreviewed·2022-05-24
CVE-2018-18509 [MEDIUM] CWE-347 GHSA-pqr9-248w-h9pf: A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the show
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content. This vulnerability affects Thunderbird < 60.5.1.
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2019-10-01·CVSS 7.8
CVE-2016-10905 linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that a race condition existed in the GFS2 file system in
the Linux kernel. A local attacker could possibly use this to cause a
denial of service (system crash). (CVE-2016-10905)
It was discovered that the IPv6 implementation in the Linux kernel did not
properly validate socket options in some situations. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-18509)
It was discovered that the USB gadget Midi driver in the Linux kernel
contained a double-free vulnerability when handling certain error
conditions. A local attacker could use this to cause a denial of service
(system crash). (CVE-2018-20961)
It was discovered that th
OSV
CVE-2018-18509: A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the show
osv·2019-04-26·CVSS 5.3
CVE-2018-18509 [MEDIUM] CVE-2018-18509: A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the show
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content. This vulnerability affects Thunderbird < 60.5.1.
OSV
thunderbird vulnerabilities
osv·2019-02-26·CVSS 5.5
CVE-2016-5824 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
A use-after-free was discovered in libical. If a user were tricked in to
opening a specially crafted ICS calendar file, an attacker could
potentially exploit this to cause a denial of service. (CVE-2016-5824)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service, or execute
arbitrary code. (CVE-2018-18356, CVE-2018-18500, CVE-2019-5785)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
gain additional privileges by escaping the sandbox, or execute arbitr
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2019-02-26·CVSS 5.5
CVE-2016-5824 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
A use-after-free was discovered in libical. If a user were tricked in to
opening a specially crafted ICS calendar file, an attacker could
potentially exploit this to cause a denial of service. (CVE-2016-5824)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service, or execute
arbitrary code. (CVE-2018-18356, CVE-2018-18500, CVE-2019-5785)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
g
Red Hat
thunderbird: flaw in verification of S/MIME signature resulting in signature spoofing
vendor_redhat·2019-02-14·CVSS 5.3
CVE-2018-18509 [MEDIUM] CWE-451 thunderbird: flaw in verification of S/MIME signature resulting in signature spoofing
thunderbird: flaw in verification of S/MIME signature resulting in signature spoofing
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content. This vulnerability affects Thunderbird < 60.5.1.
Debian
CVE-2018-18509: thunderbird - A flaw during verification of certain S/MIME signatures causes emails to be show...
vendor_debian·2018·CVSS 5.3
CVE-2018-18509 [MEDIUM] CVE-2018-18509: thunderbird - A flaw during verification of certain S/MIME signatures causes emails to be show...
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content. This vulnerability affects Thunderbird < 60.5.1.
Scope: local
bookworm: resolved (fixed in 1:60.5.1-1)
bullseye: resolved (fixed in 1:60.5.1-1)
forky: resolved (fixed in 1:60.5.1-1)
sid: resolved (fixed in 1:60.5.1-1)
trixie: resolved (fixed in 1:60.5.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-18509 thunderbird: flaw in verification of S/MIME signature resulting in signature spoofing
bugzilla·2019-02-15·CVSS 5.3
CVE-2018-18509 [MEDIUM] CVE-2018-18509 thunderbird: flaw in verification of S/MIME signature resulting in signature spoofing
CVE-2018-18509 thunderbird: flaw in verification of S/MIME signature resulting in signature spoofing
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content.
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-06/#CVE-2018-18509
Discussion:
Created thunderbird tracking bugs for this issue:
Affects: fedora-all [bug 1677614]
---
Reference:
https://bugzilla.mozilla.org/show_bug.cgi?id=1507218
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https:
Bugzilla
CVE-2018-18509 thunderbird: flaw in verification of S/MIME signature resulting in signature spoofing [fedora-all]
bugzilla·2019-02-15·CVSS 5.3
CVE-2018-18509 [MEDIUM] CVE-2018-18509 thunderbird: flaw in verification of S/MIME signature resulting in signature spoofing [fedora-all]
CVE-2018-18509 thunderbird: flaw in verification of S/MIME signature resulting in signature spoofing [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
Wrong Thunderbird S/MIME signature status shown, if CMS signed data has data content.
bugzilla·2018-11-14
[MEDIUM] Wrong Thunderbird S/MIME signature status shown, if CMS signed data has data content.
Wrong Thunderbird S/MIME signature status shown, if CMS signed data has data content.
Created attachment 9025094
eContentConfusion.eml
User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:63.0) Gecko/20100101 Firefox/63.0
Steps to reproduce:
Build a special *.eml file with conflicting requirements. I used the der2ascii tool¹ to create this email. The error is further explained in the uploaded file itself.
¹ https://github.com/google/der-ascii
Actual results:
The email is showed as being signed by Damian Poddebniak (me), even though the text can be freely changed.
Expected results:
Error out due to "conflicting requirements" OR display of the verified content only.
Discussion:
This works in the latest Thunderbirds (60.0, 60.2.1, 60.3.0) but I expect it to work in all (?) previous ver
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00043.htmlhttp://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.htmlhttp://seclists.org/fulldisclosure/2019/Apr/38http://www.openwall.com/lists/oss-security/2019/04/30/4https://access.redhat.com/errata/RHSA-2019:1144https://bugzilla.mozilla.org/show_bug.cgi?id=1507218https://github.com/RUB-NDS/Johnny-You-Are-Firedhttps://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdfhttps://www.mozilla.org/security/advisories/mfsa2019-06/http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00043.htmlhttp://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.htmlhttp://seclists.org/fulldisclosure/2019/Apr/38http://www.openwall.com/lists/oss-security/2019/04/30/4https://access.redhat.com/errata/RHSA-2019:1144https://bugzilla.mozilla.org/show_bug.cgi?id=1507218https://github.com/RUB-NDS/Johnny-You-Are-Firedhttps://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdfhttps://www.mozilla.org/security/advisories/mfsa2019-06/
2019-04-26
Published