CVE-2018-5184

Source
Severity High
Remote Yes
Type Information disclosure
Description
A security issue has been found in Thunderbird before 52.8, where using remote content in S/MIME encrypted messages can lead to the disclosure of plaintext via chosen-ciphertext attack.
Group Package Affected Fixed Severity Status Ticket
AVG-707 thunderbird 52.7.0-2 52.8.0-1 Critical Fixed
Date Advisory Group Package Severity Description
21 May 2018 ASA-201805-21 AVG-707 thunderbird Critical multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2018-13/#CVE-2018-5184
https://bugzilla.mozilla.org/show_bug.cgi?id=1411592
Notes
Very likely related to CVE-2017-17689 but Mozilla did not include any details so..