Vulnerability Name:

CVE-2018-12373 (CCN-146000)

Assigned:2018-05-27
Published:2018-05-27
Updated:2019-10-03
Summary:dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderbird < 52.9.
CVSS v3 Severity:6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
6.5 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
5.7 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
CWE-212
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2018-12373

Source: BID
Type: Third Party Advisory, VDB Entry
104613

Source: CCN
Type: BID-104613
Mozilla Thunderbird MFSA2018-18 Multiple Information Disclosure Vulnerabilities

Source: REDHAT
Type: Third Party Advisory
RHSA-2018:2251

Source: REDHAT
Type: Third Party Advisory
RHSA-2018:2252

Source: CONFIRM
Type: Issue Tracking, Permissions Required, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1464056

Source: CONFIRM
Type: Issue Tracking, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1464667

Source: XF
Type: UNKNOWN
mozilla-thunderbird-cve201812373-info-disc(146000)

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20180714 [SECURITY] [DLA 1425-1] thunderbird security update

Source: GENTOO
Type: Third Party Advisory
GLSA-201811-13

Source: UBUNTU
Type: Third Party Advisory
USN-3714-1

Source: DEBIAN
Type: Third Party Advisory
DSA-4244

Source: CCN
Type: Mozilla Foundation Security Advisory 2018-18
Security vulnerabilities fixed in Thunderbird 52.9

Source: CONFIRM
Type: Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2018-18/

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2018-12373

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mozilla:thunderbird:*:*:*:*:*:*:*:* (Version < 52.9.0)

  • Configuration 2:
  • cpe:/o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:7.5:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:7.6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:6::client:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*

  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*

  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*

  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:51562
    P
    Security update for dpkg (Low)
    2022-11-18
    oval:org.opensuse.security:def:645
    P
    Security update for php7 (Moderate) (in QA)
    2022-10-04
    oval:org.opensuse.security:def:201812373
    V
    CVE-2018-12373
    2022-09-02
    oval:org.opensuse.security:def:4670
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP5) (Important)
    2022-08-10
    oval:org.opensuse.security:def:3546
    P
    libICE6-1.0.8-12.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:95176
    P
    MozillaThunderbird-91.8.0-150200.8.65.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:4625
    P
    Security update for the Linux Kernel (Live Patch 22 for SLE 12 SP5) (Important)
    2022-06-06
    oval:org.opensuse.security:def:4605
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 12 SP5) (Important)
    2022-05-20
    oval:org.opensuse.security:def:4597
    P
    Security update for the Linux Kernel (Live Patch 27 for SLE 12 SP5) (Important)
    2022-05-09
    oval:org.opensuse.security:def:64678
    P
    Security update for apache2 (Important)
    2022-01-17
    oval:org.opensuse.security:def:111905
    P
    MozillaThunderbird-91.1.1-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:4730
    P
    Security update for the Linux RT Kernel (Important)
    2021-12-10
    oval:org.opensuse.security:def:1137
    P
    Security update for the Linux Kernel (Important)
    2021-11-16
    oval:org.opensuse.security:def:105478
    P
    MozillaThunderbird-91.1.1-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:66933
    P
    Security update for gd (Moderate)
    2021-09-27
    oval:org.opensuse.security:def:71352
    P
    openssh-7.9p1-4.7 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:64765
    P
    Security update for ghostscript (Critical)
    2021-09-15
    oval:org.opensuse.security:def:70289
    P
    Security update for libesmtp (Important)
    2021-09-03
    oval:org.opensuse.security:def:47659
    P
    krb5-appl-clients-1.0.3-1.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47673
    P
    libXdmcp6-1.1.1-12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47794
    P
    libtasn1-4.9-3.5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47987
    P
    cyrus-sasl-2.1.26-8.7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47658
    P
    krb5-1.12.5-40.28.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48119
    P
    libgraphite2-3-1.3.1-10.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48211
    P
    libunwind-1.1-11.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:101020
    P
    minicom-2.7.1-1.19 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1732
    P
    open-vm-tools-desktop-11.2.5-1.17 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1773
    P
    Security update for MozillaThunderbird (Important)
    2021-07-22
    oval:org.opensuse.security:def:68012
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 15 SP1) (Important)
    2021-07-14
    oval:org.opensuse.security:def:4749
    P
    Security update for cryptctl (Important)
    2021-06-23
    oval:org.opensuse.security:def:66841
    P
    Security update for freeradius-server (Moderate)
    2021-06-23
    oval:org.opensuse.security:def:48784
    P
    libFLAC++6-32bit-1.3.0-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48657
    P
    yast2-3.1.206-36.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48815
    P
    raptor-2.0.10-3.67 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48886
    P
    telepathy-gabble-0.18.3-5.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48359
    P
    DirectFB-1.7.1-6.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48719
    P
    freerdp-1.0.2-7.9 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48573
    P
    libzip2-0.11.1-12.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:73624
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:68112
    P
    Security update for the Linux Kernel (Live Patch 14 for SLE 15 SP1) (Important)
    2021-03-17
    oval:org.opensuse.security:def:52011
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-02-19
    oval:org.opensuse.security:def:51728
    P
    Security update for openvswitch (Important)
    2021-02-12
    oval:org.opensuse.security:def:94307
    P
    MozillaThunderbird-68.8.0-3.80.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103747
    P
    MozillaThunderbird-60.6.1-3.28.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63563
    P
    MozillaThunderbird-60.6.1-3.28.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107686
    P
    MozillaThunderbird-68.8.0-3.80.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71465
    P
    cups-filters-1.25.0-1.107 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117201
    P
    MozillaThunderbird-68.8.0-3.80.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63604
    P
    MozillaThunderbird-68.8.0-3.80.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2474
    P
    MozillaThunderbird-60.6.1-3.28.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:90092
    P
    MozillaThunderbird-60.6.1-3.28.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2515
    P
    MozillaThunderbird-68.8.0-3.80.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:5544
    P
    Security update for xen (Important)
    2020-12-02
    oval:org.opensuse.security:def:4715
    P
    Security update for libxml2 (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:5575
    P
    Security update for Mozilla Thunderbird (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4879
    P
    Security update for virglrenderer (Important)
    2020-12-02
    oval:org.opensuse.security:def:4822
    P
    Security update for gnuplot (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4886
    P
    Security update for postgresql10 and postgresql12 (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4847
    P
    Security update for dovecot23 (Important)
    2020-12-02
    oval:org.opensuse.security:def:4893
    P
    Security update for graphviz (Low)
    2020-12-02
    oval:org.opensuse.security:def:4906
    P
    Security update for salt (Critical)
    2020-12-02
    oval:org.opensuse.security:def:26471
    P
    Security update for Mozilla Thunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53675
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:25365
    P
    Security update for grub2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:73506
    P
    jcl-over-slf4j on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52210
    P
    Security update for e2fsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53749
    P
    Security update for Mozilla Thunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70184
    P
    osc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25449
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:52282
    P
    Security update for pcp (Important)
    2020-12-01
    oval:org.opensuse.security:def:50888
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:52119
    P
    Security update for gnutls (Important)
    2020-12-01
    oval:org.opensuse.security:def:25599
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26436
    P
    Security update for pdns-recursor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52318
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:50910
    P
    Security update for python-PyYAML (Important)
    2020-12-01
    oval:org.opensuse.security:def:25740
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25652
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:50119
    P
    apache2-mod_php7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52399
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:51048
    P
    Security update for runc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25754
    P
    Security update for flash-player (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25036
    P
    Security update for sqlite3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50173
    P
    MozillaThunderbird on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25025
    P
    Security update for python3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:51285
    P
    Security update for python (Important)
    2020-12-01
    oval:org.opensuse.security:def:25798
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25100
    P
    Security update for qemu (Important)
    2020-12-01
    oval:org.opensuse.security:def:50887
    P
    Security update for permissions (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50160
    P
    libpskc-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51456
    P
    Security update for python3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25227
    P
    Security update for wicked (Important)
    2020-12-01
    oval:org.opensuse.security:def:50214
    P
    MozillaThunderbird on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25308
    P
    Security update for java-1_7_1-ibm (Moderate)
    2020-12-01
    oval:com.ubuntu.bionic:def:2018123730000000
    V
    CVE-2018-12373 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-10-18
    oval:com.ubuntu.trusty:def:201812373000
    V
    CVE-2018-12373 on Ubuntu 14.04 LTS (trusty) - medium.
    2018-10-18
    oval:com.ubuntu.xenial:def:2018123730000000
    V
    CVE-2018-12373 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-10-18
    oval:com.ubuntu.xenial:def:201812373000
    V
    CVE-2018-12373 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-10-18
    oval:com.ubuntu.bionic:def:201812373000
    V
    CVE-2018-12373 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-10-18
    oval:com.redhat.rhsa:def:20182251
    P
    RHSA-2018:2251: thunderbird security update (Important)
    2018-07-24
    oval:com.redhat.rhsa:def:20182252
    P
    RHSA-2018:2252: thunderbird security update (Important)
    2018-07-24
    oval:com.ubuntu.artful:def:201812373000
    V
    CVE-2018-12373 on Ubuntu 17.10 (artful) - medium.
    2018-07-05
    BACK
    mozilla thunderbird *
    redhat enterprise linux 6.0
    redhat enterprise linux 7.0
    redhat enterprise linux 7.5
    redhat enterprise linux 7.6
    redhat enterprise linux desktop 6.0
    redhat enterprise linux desktop 7.0
    redhat enterprise linux server 6.0
    redhat enterprise linux server 7.0
    redhat enterprise linux workstation 6.0
    redhat enterprise linux workstation 7.0
    debian debian linux 8.0
    debian debian linux 9.0
    canonical ubuntu linux 14.04
    canonical ubuntu linux 16.04
    canonical ubuntu linux 17.10
    canonical ubuntu linux 18.04