CVE-2018-5184
published 2018-06-11CVE-2018-5184: Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
PriorityP336high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.80%
76.2th percentile
Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | thunderbird | < thunderbird 1:52.8.0-1 (bookworm) | thunderbird 1:52.8.0-1 (bookworm) |
| mozilla | thunderbird | < 52.8.0 | 52.8.0 |
| mozilla | thunderbird | >= 0 < 1:52.8.0-1 | 1:52.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0-1 | 1:52.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0-1 | 1:52.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0-1 | 1:52.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0+build1-0ubuntu0.14.04.1 | 1:52.8.0+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0+build1-0ubuntu0.16.04.1 | 1:52.8.0+build1-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0+build1-0ubuntu0.18.04.1 | 1:52.8.0+build1-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= unspecified < 52.8 | 52.8 |
| mozilla | thunderbird_esr | < 52.8.0 | 52.8.0 |
| mozilla | thunderbird_esr | >= unspecified < 52.8 | 52.8 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2018-05-25·CVSS 9.8
CVE-2018-5150 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service
via application crash, install lightweight themes without user
interaction, or execute arbitrary code. (CVE-2018-5150, CVE-2018-5154,
CVE-2018-5155, CVE-2018-5159, CVE-2018-5168, CVE-2018-5178)
An issue was discovered when processing message headers in Thunderbird. If
a user were tricked in to opening a specially crafted message, an attacker
could potentially exploit this to cause a denial of service via
application hang. (CVE-2018-5161)
It was discovered encrypted messages coul
Red Hat
Mozilla: Full plaintext recovery in S/MIME via chosen-ciphertext attack
vendor_redhat·2018-05-18·CVSS 7.5
CVE-2018-5184 [HIGH] CWE-200 Mozilla: Full plaintext recovery in S/MIME via chosen-ciphertext attack
Mozilla: Full plaintext recovery in S/MIME via chosen-ciphertext attack
Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
Package: thunderbird (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-5184: thunderbird - Using remote content in encrypted messages can lead to the disclosure of plainte...
vendor_debian·2018·CVSS 7.5
CVE-2018-5184 [HIGH] CVE-2018-5184: thunderbird - Using remote content in encrypted messages can lead to the disclosure of plainte...
Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
Scope: local
bookworm: resolved (fixed in 1:52.8.0-1)
bullseye: resolved (fixed in 1:52.8.0-1)
forky: resolved (fixed in 1:52.8.0-1)
sid: resolved (fixed in 1:52.8.0-1)
trixie: resolved (fixed in 1:52.8.0-1)
GHSA
GHSA-p5x3-568x-9fq9: Using remote content in encrypted messages can lead to the disclosure of plaintext
ghsa_unreviewed·2022-05-14
CVE-2018-5184 [HIGH] CWE-326 GHSA-p5x3-568x-9fq9: Using remote content in encrypted messages can lead to the disclosure of plaintext
Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
OSV
CVE-2018-5184: Using remote content in encrypted messages can lead to the disclosure of plaintext
osv·2018-06-11·CVSS 7.5
CVE-2018-5184 [HIGH] CVE-2018-5184: Using remote content in encrypted messages can lead to the disclosure of plaintext
Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
OSV
thunderbird vulnerabilities
osv·2018-05-25·CVSS 9.8
CVE-2018-5150 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service
via application crash, install lightweight themes without user
interaction, or execute arbitrary code. (CVE-2018-5150, CVE-2018-5154,
CVE-2018-5155, CVE-2018-5159, CVE-2018-5168, CVE-2018-5178)
An issue was discovered when processing message headers in Thunderbird. If
a user were tricked in to opening a specially crafted message, an attacker
could potentially exploit this to cause a denial of service via
application hang. (CVE-2018-5161)
It was discovered encrypted messages could leak plaintext via the src
attribute of remote images or links. An
No detection rules found.
No public exploits indexed.
Bugzilla
remote content in OpenPGP encrypted emails not blocked like it should
bugzilla·2024-10-21·CVSS 7.5
[HIGH] remote content in OpenPGP encrypted emails not blocked like it should
remote content in OpenPGP encrypted emails not blocked like it should
Testing bug 1924058 made me realize we're not hard blocking remote content for OpenPGP encrypted emails the way we're supposed to (only S/MIME), see bug 1411592.
This check is here: https://searchfox.org/comm-central/rev/57782ef9cbf3f0fccb709b33db0bda808101bc02/mailnews/base/src/nsMsgContentPolicy.cpp#321
Another case of confusion due to OpenPGP instead using EnigmailURIs.isEncryptedUri. We should unify this check.
Discussion:
Created attachment 9433680
Bug 1925929 - Forbid viewing remote content in encrypted OpenPGP messages. r=mkmelin
---
Pushed by [email protected]:
https://hg.mozilla.org/comm-central/rev/f4a450f4d1f5
Forbid viewing remote content in encrypted OpenPGP messages. r=mkmelin
---
Comment on atta
Bugzilla
CVE-2018-5184 Mozilla: Full plaintext recovery in S/MIME via chosen-ciphertext attack
bugzilla·2018-05-21·CVSS 7.5
CVE-2018-5184 [HIGH] CVE-2018-5184 Mozilla: Full plaintext recovery in S/MIME via chosen-ciphertext attack
CVE-2018-5184 Mozilla: Full plaintext recovery in S/MIME via chosen-ciphertext attack
Using remote content in encrypted messages can lead to the disclosure of plaintext.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-13/#CVE-2018-5184
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1725 https://access.redhat.com/errata/RHSA-2018:1725
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1726 https://access.redhat.com/errata/RHSA-2018:1726
Bugzilla
CVE-2017-17689 S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
bugzilla·2018-05-14·CVSS 5.9
CVE-2017-17689 [MEDIUM] CVE-2017-17689 S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
CVE-2017-17689 S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
Vulnerabilities in S/MIME specification can be abused by so-called CBC gadget attacks to exfiltrate the plaintext from encrypted email. Attacker having access to encrypted emails of a victim can modify them to inject an image tag into them and create a single encrypted body part that exfiltrates its own plaintext when the victim opens the attacker email.
External References:
https://efail.de/
Discussion:
Created evolution tracking bugs for this issue:
Affects: fedora-all [bug 1577910]
Created kmail tracking bugs for this issue:
Affects: fedora-all [bug 1577911]
Created thunderbird tracking bugs for this issue:
Affects: fedora-all [bug 1577914]
Created thunderbird-enigmail tracking
http://www.securityfocus.com/bid/104240http://www.securitytracker.com/id/1040946https://access.redhat.com/errata/RHSA-2018:1725https://access.redhat.com/errata/RHSA-2018:1726https://bugzilla.mozilla.org/show_bug.cgi?id=1411592https://lists.debian.org/debian-lts-announce/2018/05/msg00013.htmlhttps://security.gentoo.org/glsa/201811-13https://usn.ubuntu.com/3660-1/https://www.debian.org/security/2018/dsa-4209https://www.mozilla.org/security/advisories/mfsa2018-13/http://www.securityfocus.com/bid/104240http://www.securitytracker.com/id/1040946https://access.redhat.com/errata/RHSA-2018:1725https://access.redhat.com/errata/RHSA-2018:1726https://bugzilla.mozilla.org/show_bug.cgi?id=1411592https://lists.debian.org/debian-lts-announce/2018/05/msg00013.htmlhttps://security.gentoo.org/glsa/201811-13https://usn.ubuntu.com/3660-1/https://www.debian.org/security/2018/dsa-4209https://www.mozilla.org/security/advisories/mfsa2018-13/
2018-06-11
Published