#VU17703 Spoofing attack in Mozilla Thunderbird - CVE-2018-18509
Published: February 14, 2019
Mozilla Thunderbird
Mozilla
Description
The vulnerability exists due to a flaw during verification of certain S/MIME signatures causes emails can be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. A remote attacker can reuse a valid S/MIME signature to craft an email message with arbitrary content.