Mozilla Thunderbird File Attachment Spoofing Vulnerability

BID:16271

Info

Mozilla Thunderbird File Attachment Spoofing Vulnerability

Bugtraq ID: 16271
Class: Design Error
CVE: CVE-2006-0236
Remote: Yes
Local: No
Published: Jan 17 2006 12:00AM
Updated: Dec 20 2006 09:32PM
Credit: Discovered by Andreas Sandblad, Secunia Research.
Vulnerable: Mozilla Thunderbird 1.5 beta 2
Mozilla Thunderbird 1.0.7
Mozilla Thunderbird 1.0.6
Mozilla Thunderbird 1.0.5
Mozilla Thunderbird 1.0.2
Mozilla Thunderbird 1.0.1
Mozilla Thunderbird 1.0
Mandriva Linux Mandrake 2006.0 x86_64
Mandriva Linux Mandrake 2006.0
Not Vulnerable: Mozilla Thunderbird 1.5

Discussion

Mozilla Thunderbird File Attachment Spoofing Vulnerability

Mozilla Thunderbird is prone to a file-attachment spoofing vulnerability.

Successful exploitation may allow attackers to place malicious files on a user's computer by tricking users into saving seemingly safe attachments. If the user subsequently opens the file, this vulnerability may facilitate arbitrary code execution in the context of the user.

Thunderbird versions prior to 1.5 are affected.

Exploit / POC

Mozilla Thunderbird File Attachment Spoofing Vulnerability

An exploit is not required.

Solution / Fix

Mozilla Thunderbird File Attachment Spoofing Vulnerability

Solution:
Mozilla Thunderbird 1.5 has been released to address this issue.

Mandriva has released advisory MDKSA-2006:021, along with fixes to address this issue. Please see the referenced advisory for further information.


Mozilla Thunderbird 1.0

Mozilla Thunderbird 1.0.1

Mozilla Thunderbird 1.0.2

Mozilla Thunderbird 1.0.5

Mozilla Thunderbird 1.0.6

Mozilla Thunderbird 1.0.7

Mozilla Thunderbird 1.5 beta 2

References

Mozilla Thunderbird File Attachment Spoofing Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report