Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 68.1 and Thunderbird < 60.9.
| Software | From | Fixed in |
|---|---|---|
| mozilla / thunderbird | - | 60.9.0 |
| mozilla / thunderbird | 68.0 | 68.1.0 |