Mozilla Thunderbird Insecure SMTP Authentication Protocol Negotiation Weakness
BID:15106
Info
Mozilla Thunderbird Insecure SMTP Authentication Protocol Negotiation Weakness
| Bugtraq ID: | 15106 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 14 2005 12:00AM |
| Updated: | Oct 14 2005 12:00AM |
| Credit: | Discovery is credited to Thomas Henlich <[email protected]>. |
| Vulnerable: |
Mozilla Thunderbird 1.5 beta 2 Mozilla Thunderbird 1.0.7 |
| Not Vulnerable: | |
Discussion
Mozilla Thunderbird Insecure SMTP Authentication Protocol Negotiation Weakness
Mozilla Thunderbird is prone to an insecure SMTP authentication protocol negotiation weakness.
Reports indicate that the application uses PLAIN authentication if CRAM-MD5 or STARTTLS between a client and a server cannot be established. This can allow an attacker to obtain credentials by sniffing network traffic.
This issue can also allow an attacker to carry out man in the middle attacks by establishing a malicious server and causing CRAM-MD5 or STARTTLS to fail followed by harvesting authentication credentials of vulnerable users.
Mozilla Thunderbird 1.0.7 and 1.5 Beta 2 were reported to be vulnerable. Other versions may be affected as well.
Mozilla Thunderbird is prone to an insecure SMTP authentication protocol negotiation weakness.
Reports indicate that the application uses PLAIN authentication if CRAM-MD5 or STARTTLS between a client and a server cannot be established. This can allow an attacker to obtain credentials by sniffing network traffic.
This issue can also allow an attacker to carry out man in the middle attacks by establishing a malicious server and causing CRAM-MD5 or STARTTLS to fail followed by harvesting authentication credentials of vulnerable users.
Mozilla Thunderbird 1.0.7 and 1.5 Beta 2 were reported to be vulnerable. Other versions may be affected as well.
Exploit / POC
Mozilla Thunderbird Insecure SMTP Authentication Protocol Negotiation Weakness
An exploit is not required.
An exploit is not required.
Solution / Fix
Mozilla Thunderbird Insecure SMTP Authentication Protocol Negotiation Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Mozilla Thunderbird Insecure SMTP Authentication Protocol Negotiation Weakness
References:
References:
- Cisco NX-OS Download Page (Cisco)
- Mozilla Thunderbird SMTP down-negotiation weakness (Thomas Henlich)