Thunderbird Multiple Vulnerabilities


Recommended Posts

VERIFY ADVISORY: SECUNIA ADVISORY ID: SA20382

CRITICAL: Highly critical

IMPACT: Security Bypass, Cross Site Scripting, System access

WHERE: From remote

SOFTWARE:

Mozilla Thunderbird 0.x

Mozilla Thunderbird 1.0.x

Mozilla Thunderbird 1.5.x

DESCRIPTION:

Multiple vulnerabilities have been reported in Thunderbird, which can

be exploited by malicious people to bypass certain security

restrictions, conduct cross-site scripting and HTTP response

smuggling attacks, and potentially compromise a user's system.

For more information, see vulnerabilities #1, #2, #3, #5, #6, #7, and

#9 in: SA20376

Successful exploitation of some of the vulnerabilities requires that

JavaScript is enabled (not enabled by default).

The following vulnerability has also been reported:

The vulnerability is caused due to a double-free error within the

processing of large VCards with invalid base64 characters. This may

be exploited to execute arbitrary code.

SOLUTION: Update to version 1.5.0.4.

PROVIDED AND/OR DISCOVERED BY: Masatoshi Kimura

ORIGINAL ADVISORY:

http://www.mozilla.org/security/anno...sa2006-40.html

OTHER REFERENCES:SA20376

Please note: The information, which this Secunia Advisory is based upon, comes from third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...