Medium severity6.5NVD Advisory· Published Sep 27, 2019· Updated Jun 17, 2026
CVE-2019-11739
CVE-2019-11739
Description
Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 68.1 and Thunderbird < 60.9.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*range: <60.9.0
- (no CPE)range: <68.1, <60.9
- (no CPE)range: unspecified
- osv-coords7 versionspkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/enigmail&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/enigmail&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP1
< 68.1.1-lp150.3.51.1+ 6 more
- (no CPE)range: < 68.1.1-lp150.3.51.1
- (no CPE)range: < 68.1.1-lp151.2.13.1
- (no CPE)range: < 91.1.1-1.1
- (no CPE)range: < 2.1.2-lp150.34.1
- (no CPE)range: < 2.1.2-lp151.2.6.1
- (no CPE)range: < 68.1.1-3.51.1
- (no CPE)range: < 68.1.1-3.51.1
Patches
Vulnerability mechanics
References
6- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions RequiredVendor Advisory
- www.mozilla.org/security/advisories/mfsa2019-29/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2019-30/nvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.htmlnvd
- usn.ubuntu.com/4150-1/nvd
News mentions
0No linked articles in our index yet.