CVE-2018-5185
published 2018-06-11CVE-2018-5185: Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
PriorityP427medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
EPSS
1.56%
72.6th percentile
Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | thunderbird | < thunderbird 1:52.8.0-1 (bookworm) | thunderbird 1:52.8.0-1 (bookworm) |
| mozilla | thunderbird | < 52.8.0 | 52.8.0 |
| mozilla | thunderbird | >= 0 < 1:52.8.0-1 | 1:52.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0-1 | 1:52.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0-1 | 1:52.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0-1 | 1:52.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0+build1-0ubuntu0.14.04.1 | 1:52.8.0+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0+build1-0ubuntu0.16.04.1 | 1:52.8.0+build1-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0+build1-0ubuntu0.18.04.1 | 1:52.8.0+build1-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= unspecified < 52.8 | 52.8 |
| mozilla | thunderbird_esr | < 52.8.0 | 52.8.0 |
| mozilla | thunderbird_esr | >= unspecified < 52.8 | 52.8 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2018-05-25·CVSS 9.8
CVE-2018-5150 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service
via application crash, install lightweight themes without user
interaction, or execute arbitrary code. (CVE-2018-5150, CVE-2018-5154,
CVE-2018-5155, CVE-2018-5159, CVE-2018-5168, CVE-2018-5178)
An issue was discovered when processing message headers in Thunderbird. If
a user were tricked in to opening a specially crafted message, an attacker
could potentially exploit this to cause a denial of service via
application hang. (CVE-2018-5161)
It was discovered encrypted messages coul
Red Hat
Mozilla: Leaking plaintext through HTML forms
vendor_redhat·2018-05-18·CVSS 6.5
CVE-2018-5185 [MEDIUM] CWE-200 Mozilla: Leaking plaintext through HTML forms
Mozilla: Leaking plaintext through HTML forms
Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
Package: thunderbird (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-5185: thunderbird - Plaintext of decrypted emails can leak through by user submitting an embedded fo...
vendor_debian·2018·CVSS 6.5
CVE-2018-5185 [MEDIUM] CVE-2018-5185: thunderbird - Plaintext of decrypted emails can leak through by user submitting an embedded fo...
Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
Scope: local
bookworm: resolved (fixed in 1:52.8.0-1)
bullseye: resolved (fixed in 1:52.8.0-1)
forky: resolved (fixed in 1:52.8.0-1)
sid: resolved (fixed in 1:52.8.0-1)
trixie: resolved (fixed in 1:52.8.0-1)
GHSA
GHSA-jx89-4j89-fggc: Plaintext of decrypted emails can leak through by user submitting an embedded form
ghsa_unreviewed·2022-05-13
CVE-2018-5185 [MEDIUM] CWE-311 GHSA-jx89-4j89-fggc: Plaintext of decrypted emails can leak through by user submitting an embedded form
Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
OSV
CVE-2018-5185: Plaintext of decrypted emails can leak through by user submitting an embedded form
osv·2018-06-11·CVSS 6.5
CVE-2018-5185 [MEDIUM] CVE-2018-5185: Plaintext of decrypted emails can leak through by user submitting an embedded form
Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
OSV
thunderbird vulnerabilities
osv·2018-05-25·CVSS 9.8
CVE-2018-5150 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service
via application crash, install lightweight themes without user
interaction, or execute arbitrary code. (CVE-2018-5150, CVE-2018-5154,
CVE-2018-5155, CVE-2018-5159, CVE-2018-5168, CVE-2018-5178)
An issue was discovered when processing message headers in Thunderbird. If
a user were tricked in to opening a specially crafted message, an attacker
could potentially exploit this to cause a denial of service via
application hang. (CVE-2018-5161)
It was discovered encrypted messages could leak plaintext via the src
attribute of remote images or links. An
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5185 Mozilla: Leaking plaintext through HTML forms
bugzilla·2018-05-21·CVSS 6.5
CVE-2018-5185 [MEDIUM] CVE-2018-5185 Mozilla: Leaking plaintext through HTML forms
CVE-2018-5185 Mozilla: Leaking plaintext through HTML forms
Plaintext of decrypted emails can leak through by user submitting an embedded form.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-13/#CVE-2018-5185
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1725 https://access.redhat.com/errata/RHSA-2018:1725
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1726 https://access.redhat.com/errata/RHSA-2018:1726
Bugzilla
CVE-2017-17689 S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
bugzilla·2018-05-14·CVSS 5.9
CVE-2017-17689 [MEDIUM] CVE-2017-17689 S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
CVE-2017-17689 S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
Vulnerabilities in S/MIME specification can be abused by so-called CBC gadget attacks to exfiltrate the plaintext from encrypted email. Attacker having access to encrypted emails of a victim can modify them to inject an image tag into them and create a single encrypted body part that exfiltrates its own plaintext when the victim opens the attacker email.
External References:
https://efail.de/
Discussion:
Created evolution tracking bugs for this issue:
Affects: fedora-all [bug 1577910]
Created kmail tracking bugs for this issue:
Affects: fedora-all [bug 1577911]
Created thunderbird tracking bugs for this issue:
Affects: fedora-all [bug 1577914]
Created thunderbird-enigmail tracking
http://www.securityfocus.com/bid/104240http://www.securitytracker.com/id/1040946https://access.redhat.com/errata/RHSA-2018:1725https://access.redhat.com/errata/RHSA-2018:1726https://bugzilla.mozilla.org/show_bug.cgi?id=1450345https://lists.debian.org/debian-lts-announce/2018/05/msg00013.htmlhttps://security.gentoo.org/glsa/201811-13https://usn.ubuntu.com/3660-1/https://www.debian.org/security/2018/dsa-4209https://www.mozilla.org/security/advisories/mfsa2018-13/http://www.securityfocus.com/bid/104240http://www.securitytracker.com/id/1040946https://access.redhat.com/errata/RHSA-2018:1725https://access.redhat.com/errata/RHSA-2018:1726https://bugzilla.mozilla.org/show_bug.cgi?id=1450345https://lists.debian.org/debian-lts-announce/2018/05/msg00013.htmlhttps://security.gentoo.org/glsa/201811-13https://usn.ubuntu.com/3660-1/https://www.debian.org/security/2018/dsa-4209https://www.mozilla.org/security/advisories/mfsa2018-13/
2018-06-11
Published