CVE-2019-11755
published 2019-09-27CVE-2019-11755: A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.07%
61.2th percentile
A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message. Previous versions had only suppressed showing a digital signature for messages with an outer multipart/signed layer. This vulnerability affects Thunderbird < 68.1.1.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:68.2.1-1 (bookworm) | thunderbird 1:68.2.1-1 (bookworm) |
| mozilla | thunderbird | < 68.1.1 | 68.1.1 |
| mozilla | thunderbird | >= 0 < 1:68.2.1-1 | 1:68.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:68.2.1-1 | 1:68.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:68.2.1-1 | 1:68.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:68.2.1-1 | 1:68.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:68.7.0+build1-0ubuntu0.16.04.2 | 1:68.7.0+build1-0ubuntu0.16.04.2 |
| mozilla | thunderbird | >= 0 < 1:68.2.2+build1-0ubuntu0.18.04.1 | 1:68.2.2+build1-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= 0 < 1:68.2.1+build1-0ubuntu0.18.04.1 | 1:68.2.1+build1-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= unspecified < 68.1.1 | 68.1.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2020-04-21·CVSS 8.8
CVE-2019-11745 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, bypass
same-origin restrictions, conduct cross-site scripting (XSS) attacks, or
execute arbitrary code. (CVE-2019-11757, CVE-2019-11758, CVE-2019-11759,
CVE-2019-11760, CVE-2019-11761, CVE-2019-11762, CVE-2019-11763,
CVE-2019-11764, CVE-2019-17005, CVE-2019-17008, CVE-2019-17010,
CVE-2019-17011, CVE-2019-17012, CVE-2019-17016, CVE-2019-17017,
CVE-2019-17022, CVE-2019-17024, CVE-2019-17026, CVE-2019-20503,
CVE-2020-6798,
Ubuntu
Thunderbird regression
vendor_ubuntu·2019-12-10·CVSS 7.5
[HIGH] Thunderbird regression
Title: Thunderbird regression
Summary: USN-4202-1 caused a regression in Thunderbird.
USN-4202-1 fixed vulnerabilities in Thunderbird. After upgrading, Thunderbird
created a new profile for some users. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a specially crafted S/MIME message with an inner
encryption layer could be displayed as having a valid signature in some
circumstances, even if the signer had no access to the encrypted message.
An attacker could potentially exploit this to spoof the message author.
(CVE-2019-11755)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2019-11-26·CVSS 7.5
CVE-2019-11755 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
It was discovered that a specially crafted S/MIME message with an inner
encryption layer could be displayed as having a valid signature in some
circumstances, even if the signer had no access to the encrypted message.
An attacker could potentially exploit this to spoof the message author.
(CVE-2019-11755)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
bypass security restrictions, bypass same-origin restrictions, conduct
cross-site scripting (XSS) attacks, or execute arbitrary code.
(CVE-2019-11757, CVE-2019-11758, CVE-2019-
Red Hat
thunderbird: spoofing a message author via a crafted S/MIME
vendor_redhat·2019-09-30·CVSS 7.5
CVE-2019-11755 [HIGH] CWE-290 thunderbird: spoofing a message author via a crafted S/MIME
thunderbird: spoofing a message author via a crafted S/MIME
A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message. Previous versions had only suppressed showing a digital signature for messages with an outer multipart/signed layer. This vulnerability affects Thunderbird < 68.1.1.
Package: thunderbird (Red Hat Enterprise Linux 5) - Out of support scope
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 7) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 8) - Not affecte
Debian
CVE-2019-11755: thunderbird - A crafted S/MIME message consisting of an inner encryption layer and an outer Si...
vendor_debian·2019·CVSS 7.5
CVE-2019-11755 [HIGH] CVE-2019-11755: thunderbird - A crafted S/MIME message consisting of an inner encryption layer and an outer Si...
A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message. Previous versions had only suppressed showing a digital signature for messages with an outer multipart/signed layer. This vulnerability affects Thunderbird < 68.1.1.
Scope: local
bookworm: resolved (fixed in 1:68.2.1-1)
bullseye: resolved (fixed in 1:68.2.1-1)
forky: resolved (fixed in 1:68.2.1-1)
sid: resolved (fixed in 1:68.2.1-1)
trixie: resolved (fixed in 1:68.2.1-1)
GHSA
GHSA-42rq-cwg9-m583: A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although
ghsa_unreviewed·2022-05-24
CVE-2019-11755 [HIGH] CWE-347 GHSA-42rq-cwg9-m583: A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although
A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message. Previous versions had only suppressed showing a digital signature for messages with an outer multipart/signed layer. This vulnerability affects Thunderbird < 68.1.1.
OSV
thunderbird vulnerabilities
osv·2020-04-21·CVSS 8.8
CVE-2019-11757 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, bypass
same-origin restrictions, conduct cross-site scripting (XSS) attacks, or
execute arbitrary code. (CVE-2019-11757, CVE-2019-11758, CVE-2019-11759,
CVE-2019-11760, CVE-2019-11761, CVE-2019-11762, CVE-2019-11763,
CVE-2019-11764, CVE-2019-17005, CVE-2019-17008, CVE-2019-17010,
CVE-2019-17011, CVE-2019-17012, CVE-2019-17016, CVE-2019-17017,
CVE-2019-17022, CVE-2019-17024, CVE-2019-17026, CVE-2019-20503,
CVE-2020-6798, CVE-2020-6800, CVE-2020-6805, CVE-2020-6806, CVE-2020-6807,
CVE-2020
OSV
thunderbird regression
osv·2019-12-10·CVSS 7.5
[HIGH] thunderbird regression
thunderbird regression
USN-4202-1 fixed vulnerabilities in Thunderbird. After upgrading, Thunderbird
created a new profile for some users. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a specially crafted S/MIME message with an inner
encryption layer could be displayed as having a valid signature in some
circumstances, even if the signer had no access to the encrypted message.
An attacker could potentially exploit this to spoof the message author.
(CVE-2019-11755)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
bypass security restrictions, bypass
OSV
thunderbird vulnerabilities
osv·2019-11-26·CVSS 7.5
CVE-2019-11755 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
It was discovered that a specially crafted S/MIME message with an inner
encryption layer could be displayed as having a valid signature in some
circumstances, even if the signer had no access to the encrypted message.
An attacker could potentially exploit this to spoof the message author.
(CVE-2019-11755)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
bypass security restrictions, bypass same-origin restrictions, conduct
cross-site scripting (XSS) attacks, or execute arbitrary code.
(CVE-2019-11757, CVE-2019-11758, CVE-2019-11759, CVE-2019-11760,
CVE-2019-11761, CVE-2019-11762, CVE-2019-1176
OSV
CVE-2019-11755: A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although
osv·2019-09-27·CVSS 7.5
CVE-2019-11755 [HIGH] CVE-2019-11755: A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although
A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message. Previous versions had only suppressed showing a digital signature for messages with an outer multipart/signed layer. This vulnerability affects Thunderbird < 68.1.1.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11755 thunderbird: spoofing a message author via a crafted S/MIME [fedora-all]
bugzilla·2019-10-18·CVSS 7.5
CVE-2019-11755 [HIGH] CVE-2019-11755 thunderbird: spoofing a message author via a crafted S/MIME [fedora-all]
CVE-2019-11755 thunderbird: spoofing a message author via a crafted S/MIME [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2019-11755 thunderbird: spoofing a message author via a crafted S/MIME
bugzilla·2019-10-17·CVSS 7.5
CVE-2019-11755 [HIGH] CVE-2019-11755 thunderbird: spoofing a message author via a crafted S/MIME
CVE-2019-11755 thunderbird: spoofing a message author via a crafted S/MIME
A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message. Previous versions had only suppressed showing a digital signature for messages with an outer multipart/signed layer.
External References:
https://bugzilla.mozilla.org/show_bug.cgi?id=1240290
https://www.mozilla.org/en-US/security/advisories/mfsa2019-32/#CVE-2019-11755
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.html
Bugzilla
Susceptibility to S/MIME Message Takeover Attacks
bugzilla·2016-01-16
[MEDIUM] Susceptibility to S/MIME Message Takeover Attacks
Susceptibility to S/MIME Message Takeover Attacks
Created attachment 8708683
thb_mta.pdf
User Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:43.0) Gecko/20100101 Firefox/43.0
Build ID: 20160106234230
Steps to reproduce:
Thunderbird is susceptible to a new form of attack which builds on a flaw in the S/MIME standard.
When Alice sends a signed-then-encrypted (standard format of today's mail clients) mail to Bob, Eve blocks that mail, strips off the signature, replaces it with her own signature and sends it to Bob. Bob now believes the message originates from Eve. If he replies, he potentially discloses information to Eve. Other attack goals are also feasible. See the attachment for details.
Actual results:
Thunderbird displayed the message as validly signed.
Expected results:
D
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1240290https://lists.debian.org/debian-lts-announce/2019/11/msg00017.htmlhttps://seclists.org/bugtraq/2019/Nov/24https://usn.ubuntu.com/4202-1/https://usn.ubuntu.com/4335-1/https://www.debian.org/security/2019/dsa-4571https://www.mozilla.org/security/advisories/mfsa2019-32/http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1240290https://lists.debian.org/debian-lts-announce/2019/11/msg00017.htmlhttps://seclists.org/bugtraq/2019/Nov/24https://usn.ubuntu.com/4202-1/https://usn.ubuntu.com/4335-1/https://www.debian.org/security/2019/dsa-4571https://www.mozilla.org/security/advisories/mfsa2019-32/
2019-09-27
Published