Information disclosure in Mozilla Thunderbird - CVE-2019-11739
Published: September 13, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to an error when processing multipart messages. A remote attacker can create a specially crafted multipart/alternative message that can leak encrypted S/MIME parts when included in a a HTML reply/forward.
Affected software
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
thunderbird (Debian package)
thunderbird (Ubuntu package)
How to mitigate CVE-2019-11739
thunderbird (Debian package) - addressed in versions 1:60.9.0-1~deb9u1, 1:60.9.0-1~deb10u1
thunderbird (Ubuntu package) - addressed in versions 1:60.9.0+build1-0ubuntu0.16.04.2, 1:60.9.0+build1-0ubuntu0.18.04.1, 1:60.9.0+build1-0ubuntu0.19.04.1