Medium severity5.3NVD Advisory· Published Apr 26, 2019· Updated Jun 17, 2026
CVE-2018-18509
CVE-2018-18509
Description
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content. This vulnerability affects Thunderbird < 60.5.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8unspecified+ 2 more
- (no CPE)range: unspecified
- (no CPE)range: <60.5.1
- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*range: <60.5.1
- osv-coords4 versionspkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Package%20Hub%2012pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.0pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015
< 91.1.1-1.1+ 3 more
- (no CPE)range: < 91.1.1-1.1
- (no CPE)range: < 60.5.1-79.1
- (no CPE)range: < 60.6.1-lp150.3.37.1
- (no CPE)range: < 60.5.1-3.24.1
Patches
Vulnerability mechanics
References
8- packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.htmlnvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2019/Apr/38nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2019/04/30/4nvdMailing ListThird Party Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions RequiredVendor Advisory
- www.mozilla.org/security/advisories/mfsa2019-06/nvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2019-04/msg00043.htmlnvd
- access.redhat.com/errata/RHSA-2019:1144nvd
- github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdfnvd
News mentions
0No linked articles in our index yet.