CVE-2019-11755

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/09/2019
Last modified:
24/08/2020

Description

A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message. Previous versions had only suppressed showing a digital signature for messages with an outer multipart/signed layer. This vulnerability affects Thunderbird

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 68.1.1 (excluding)