CVE-2018-5162
published 2018-06-11CVE-2018-5162: Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird…
PriorityP337high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.98%
78.4th percentile
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | thunderbird | < thunderbird 1:52.8.0-1 (bookworm) | thunderbird 1:52.8.0-1 (bookworm) |
| mozilla | thunderbird | < 52.8.0 | 52.8.0 |
| mozilla | thunderbird | >= 0 < 1:52.8.0-1 | 1:52.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0-1 | 1:52.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0-1 | 1:52.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0-1 | 1:52.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0+build1-0ubuntu0.14.04.1 | 1:52.8.0+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0+build1-0ubuntu0.16.04.1 | 1:52.8.0+build1-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0+build1-0ubuntu0.18.04.1 | 1:52.8.0+build1-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= unspecified < 52.8 | 52.8 |
| mozilla | thunderbird_esr | < 52.8.0 | 52.8.0 |
| mozilla | thunderbird_esr | >= unspecified < 52.8 | 52.8 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-644r-rpv6-w4x6: Plaintext of decrypted emails can leak through the src attribute of remote images, or links
ghsa_unreviewed·2022-05-13
CVE-2018-5162 [HIGH] CWE-311 GHSA-644r-rpv6-w4x6: Plaintext of decrypted emails can leak through the src attribute of remote images, or links
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
OSV
CVE-2018-5162: Plaintext of decrypted emails can leak through the src attribute of remote images, or links
osv·2018-06-11·CVSS 7.5
CVE-2018-5162 [HIGH] CVE-2018-5162: Plaintext of decrypted emails can leak through the src attribute of remote images, or links
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
OSV
thunderbird vulnerabilities
osv·2018-05-25·CVSS 9.8
CVE-2018-5150 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service
via application crash, install lightweight themes without user
interaction, or execute arbitrary code. (CVE-2018-5150, CVE-2018-5154,
CVE-2018-5155, CVE-2018-5159, CVE-2018-5168, CVE-2018-5178)
An issue was discovered when processing message headers in Thunderbird. If
a user were tricked in to opening a specially crafted message, an attacker
could potentially exploit this to cause a denial of service via
application hang. (CVE-2018-5161)
It was discovered encrypted messages could leak plaintext via the src
attribute of remote images or links. An
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2018-05-25·CVSS 9.8
CVE-2018-5150 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service
via application crash, install lightweight themes without user
interaction, or execute arbitrary code. (CVE-2018-5150, CVE-2018-5154,
CVE-2018-5155, CVE-2018-5159, CVE-2018-5168, CVE-2018-5178)
An issue was discovered when processing message headers in Thunderbird. If
a user were tricked in to opening a specially crafted message, an attacker
could potentially exploit this to cause a denial of service via
application hang. (CVE-2018-5161)
It was discovered encrypted messages coul
Red Hat
Mozilla: Encrypted mail leaks plaintext through src attribute
vendor_redhat·2018-05-18·CVSS 7.5
CVE-2018-5162 [HIGH] CWE-200 Mozilla: Encrypted mail leaks plaintext through src attribute
Mozilla: Encrypted mail leaks plaintext through src attribute
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
Package: thunderbird (Red Hat Enterprise Linux 8) - Not affected
Red Hat
S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
vendor_redhat·2018-05-14·CVSS 5.9
CVE-2017-17689 [MEDIUM] CWE-200 S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
Statement: The research paper talks about use of HTML as a back channel to create an oracle for modified encrypted emails. HTML emails which use external links like "" can cause security issues if they are honored by the MUAs. Due to flaws in MIME parsers many MUAs seem to concatenate decrypted HTML mine parts which makes it easy to plan such snippets in HTML emails. Please refer to https://lists.gnupg.org/pipermail/gnupg-users/2018-May/060315.html about how GnuPG can mitigate this flaw.
For Thunderbird, this vulnerability was known as CVE-2018-5162 and reso
Debian
CVE-2018-5162: thunderbird - Plaintext of decrypted emails can leak through the src attribute of remote image...
vendor_debian·2018·CVSS 7.5
CVE-2018-5162 [HIGH] CVE-2018-5162: thunderbird - Plaintext of decrypted emails can leak through the src attribute of remote image...
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
Scope: local
bookworm: resolved (fixed in 1:52.8.0-1)
bullseye: resolved (fixed in 1:52.8.0-1)
forky: resolved (fixed in 1:52.8.0-1)
sid: resolved (fixed in 1:52.8.0-1)
trixie: resolved (fixed in 1:52.8.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10908 vdsm: calls to qemu-img are not protected by prlimit/ulimit
bugzilla·2018-07-20·CVSS 7.5
CVE-2018-10908 [HIGH] CVE-2018-10908 vdsm: calls to qemu-img are not protected by prlimit/ulimit
CVE-2018-10908 vdsm: calls to qemu-img are not protected by prlimit/ulimit
A vulnerability was found in ovirt, allowing a user to consume large amounts of memory or CPU time on the host by uploading a maliciously crafted image. This could lead to denial of service on the host, potentially impacting other users.
Discussion:
See also CVE-2015-5162, essentially the same issue on Openstack.
---
Discussion:
http://lists.nongnu.org/archive/html/qemu-block/2018-07/msg00488.html
---
Statement:
Red Hat Enterprise Virtualization 3 is now in Extended Life Phase of the support and maintenance lifecycle. Red Hat Product Security has rated this issue as having a security impact of Moderate, and it is not currently planned to be addressed in future updates of Red Hat Virtualization 3. For additi
Bugzilla
CVE-2018-5162 Mozilla: Encrypted mail leaks plaintext through src attribute
bugzilla·2018-05-21·CVSS 7.5
CVE-2018-5162 [HIGH] CVE-2018-5162 Mozilla: Encrypted mail leaks plaintext through src attribute
CVE-2018-5162 Mozilla: Encrypted mail leaks plaintext through src attribute
Plaintext of decrypted emails can leak through the src attribute of remote images, or links.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-13/#CVE-2018-5162
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1725 https://access.redhat.com/errata/RHSA-2018:1725
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1726 https://access.redhat.com/errata/RHSA-2018:1726
Bugzilla
CVE-2017-17689 S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
bugzilla·2018-05-14·CVSS 5.9
CVE-2017-17689 [MEDIUM] CVE-2017-17689 S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
CVE-2017-17689 S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
Vulnerabilities in S/MIME specification can be abused by so-called CBC gadget attacks to exfiltrate the plaintext from encrypted email. Attacker having access to encrypted emails of a victim can modify them to inject an image tag into them and create a single encrypted body part that exfiltrates its own plaintext when the victim opens the attacker email.
External References:
https://efail.de/
Discussion:
Created evolution tracking bugs for this issue:
Affects: fedora-all [bug 1577910]
Created kmail tracking bugs for this issue:
Affects: fedora-all [bug 1577911]
Created thunderbird tracking bugs for this issue:
Affects: fedora-all [bug 1577914]
Created thunderbird-enigmail tracking
Bugzilla
CVE-2017-17688 OpenPGP: CFB gadget attacks allows to exfiltrate plaintext out of encrypted emails
bugzilla·2018-05-14·CVSS 5.9
CVE-2017-17688 [MEDIUM] CVE-2017-17688 OpenPGP: CFB gadget attacks allows to exfiltrate plaintext out of encrypted emails
CVE-2017-17688 OpenPGP: CFB gadget attacks allows to exfiltrate plaintext out of encrypted emails
Vulnerabilities in OpenPGP specification can be abused by so-called CFB gadget attacks to exfiltrate the plaintext from encrypted email. Attacker having access to encrypted emails of a victim can modify them to inject an image tag into them and create a single encrypted body part that exfiltrates its own plaintext when the victim opens the attacker email.
External References:
https://efail.de/
Discussion:
Created evolution tracking bugs for this issue:
Affects: fedora-all [bug 1577910]
Created kmail tracking bugs for this issue:
Affects: fedora-all [bug 1577911]
Created thunderbird tracking bugs for this issue:
Affects: fedora-all [bug 1577914]
Created thunderbird-enigmail tracki
http://www.securityfocus.com/bid/104240http://www.securitytracker.com/id/1040946https://access.redhat.com/errata/RHSA-2018:1725https://access.redhat.com/errata/RHSA-2018:1726https://bugzilla.mozilla.org/show_bug.cgi?id=1457721https://lists.debian.org/debian-lts-announce/2018/05/msg00013.htmlhttps://security.gentoo.org/glsa/201811-13https://usn.ubuntu.com/3660-1/https://www.debian.org/security/2018/dsa-4209https://www.mozilla.org/security/advisories/mfsa2018-13/http://www.securityfocus.com/bid/104240http://www.securitytracker.com/id/1040946https://access.redhat.com/errata/RHSA-2018:1725https://access.redhat.com/errata/RHSA-2018:1726https://bugzilla.mozilla.org/show_bug.cgi?id=1457721https://lists.debian.org/debian-lts-announce/2018/05/msg00013.htmlhttps://security.gentoo.org/glsa/201811-13https://usn.ubuntu.com/3660-1/https://www.debian.org/security/2018/dsa-4209https://www.mozilla.org/security/advisories/mfsa2018-13/
2018-06-11
Published