Source: thunderbird
Severity: grave
Tags: security
Justification: user security hole

Hi,

as you might already be aware, an attack has been published against
PGP/MIME and S/MIME handling in various mail clients, including
Thunderbird.

I've already reported a bug against enigmail, since PGP handling seems
mostly restricted to enigmail, but the S/MIME part is handled directly
in Thunderbird as far as I can tell.

We'll likely have to issue a DSA too.

Regards,
-- 
Yves-Alexis

-- System Information:
Debian Release: buster/sid
  APT prefers unstable-debug
  APT policy: (500, 'unstable-debug'), (500, 'unstable'), (450, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.16.0-1-amd64 (SMP w/4 CPU cores)
Locale: LANG=fr_FR.utf8, LC_CTYPE=fr_FR.utf8 (charmap=UTF-8), 
LANGUAGE=fr_FR.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Reply via email to