Описание
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content. This vulnerability affects Thunderbird < 60.5.1.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 1:60.5.1+build2-0ubuntu0.18.04.1 |
| cosmic | released | 1:60.5.1+build2-0ubuntu0.18.10.1 |
| devel | released | 1:60.5.1+build2-0ubuntu1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [1:60.5.1+build2-0ubuntu0.14.04.1]] |
| precise/esm | DNE | |
| trusty | released | 1:60.5.1+build2-0ubuntu0.14.04.1 |
| trusty/esm | DNE | trusty was released [1:60.5.1+build2-0ubuntu0.14.04.1] |
| upstream | released | 60.5.1 |
| xenial | released | 1:60.5.1+build2-0ubuntu0.16.04.1 |
Показывать по
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3
Связанные уязвимости
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content. This vulnerability affects Thunderbird < 60.5.1.
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content. This vulnerability affects Thunderbird < 60.5.1.
A flaw during verification of certain S/MIME signatures causes emails ...
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content. This vulnerability affects Thunderbird < 60.5.1.
Уязвимость механизма проверки сигнатур S/MIME программы для работы с электронной почтой Thunderbird, связанная с неполной проверкой метаданных цифровой подписи, позволяющая нарушителю повторно подписывать письма допустимой цифровой подписью
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3