CVE Database
/

CVE-2019-11755

Back to search

CVE-2019-11755

Published: Sep 27, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message. Previous versions had only suppressed showing a digital signature for messages with an outer multipart/signed layer. This vulnerability affects Thunderbird < 68.1.1.

VendorProductVersions

Mozilla

Thunderbird

affected
unspecified - < 68.1.1

References

openSUSE-SU-2019:2248
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2249
vendor-advisory
x_refsource_SUSE
DSA-4571
vendor-advisory
x_refsource_DEBIAN
USN-4202-1
vendor-advisory
x_refsource_UBUNTU
USN-4335-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now