Spoofing attack in Mozilla Thunderbird - CVE-2019-11755
Published: September 26, 2019
Mozilla Thunderbird
Detailed vulnerability description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of S/MIME messages, consisting of an inner encryption layer and an outer SignedData layeruser-supplied data. A remote attacker can create a specially crafted message and make it look as it was signed with a valid signature. Although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message.