Lucene search

K
prionPRIOn knowledge basePRION:CVE-2018-18509
HistoryApr 26, 2019 - 5:29 p.m.

Code injection

2019-04-2617:29:00
PRIOn knowledge base
www.prio-n.com
2

6.5 Medium

AI Score

Confidence

High

0.014 Low

EPSS

Percentile

86.3%

A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren’t covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content. This vulnerability affects Thunderbird < 60.5.1.

CPENameOperatorVersion
thunderbirdlt60.5.1