Vulnerability CVE-2019-11755: Information
Description
A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message. Previous versions had only suppressed showing a digital signature for messages with an outer multipart/signed layer. This vulnerability affects Thunderbird < 68.1.1.
Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
thunderbird | sisyphus | 68.4.2-alt1 | 115.9.0-alt1 | ALT-PU-2020-1166-1 | 243898 | Fixed |
thunderbird | p10 | 68.4.2-alt1 | 115.9.0-alt1 | ALT-PU-2020-1166-1 | 243898 | Fixed |
thunderbird | p9 | 68.6.0-alt1 | 102.11.0-alt0.c9.1 | ALT-PU-2020-1515-1 | 245787 | Fixed |
thunderbird | c10f1 | 68.4.2-alt1 | 115.9.0-alt0.c10.1 | ALT-PU-2020-1166-1 | 243898 | Fixed |
thunderbird | c9f2 | 68.6.0-alt1 | 102.11.0-alt0.c9.1 | ALT-PU-2020-1515-1 | 245787 | Fixed |
thunderbird | p11 | 68.4.2-alt1 | 115.9.0-alt1 | ALT-PU-2020-1166-1 | 243898 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1240290 |
|
https://www.mozilla.org/security/advisories/mfsa2019-32/ |
|
openSUSE-SU-2019:2249 | |
openSUSE-SU-2019:2248 | |
DSA-4571 | |
20191118 [SECURITY] [DSA 4571-1] thunderbird security update | |
[debian-lts-announce] 20191118 [SECURITY] [DLA 1997-1] thunderbird security update | |
USN-4202-1 | |
USN-4335-1 |