Mozilla Thunderbird File Attachment Spoofing Vulnerability
BID:16271
Info
Mozilla Thunderbird File Attachment Spoofing Vulnerability
| Bugtraq ID: | 16271 |
| Class: | Design Error |
| CVE: |
CVE-2006-0236 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 17 2006 12:00AM |
| Updated: | Dec 20 2006 09:32PM |
| Credit: | Discovered by Andreas Sandblad, Secunia Research. |
| Vulnerable: |
Mozilla Thunderbird 1.5 beta 2 Mozilla Thunderbird 1.0.7 Mozilla Thunderbird 1.0.6 Mozilla Thunderbird 1.0.5 Mozilla Thunderbird 1.0.2 Mozilla Thunderbird 1.0.1 Mozilla Thunderbird 1.0 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 |
| Not Vulnerable: |
Mozilla Thunderbird 1.5 |
Discussion
Mozilla Thunderbird File Attachment Spoofing Vulnerability
Mozilla Thunderbird is prone to a file-attachment spoofing vulnerability.
Successful exploitation may allow attackers to place malicious files on a user's computer by tricking users into saving seemingly safe attachments. If the user subsequently opens the file, this vulnerability may facilitate arbitrary code execution in the context of the user.
Thunderbird versions prior to 1.5 are affected.
Mozilla Thunderbird is prone to a file-attachment spoofing vulnerability.
Successful exploitation may allow attackers to place malicious files on a user's computer by tricking users into saving seemingly safe attachments. If the user subsequently opens the file, this vulnerability may facilitate arbitrary code execution in the context of the user.
Thunderbird versions prior to 1.5 are affected.
Exploit / POC
Mozilla Thunderbird File Attachment Spoofing Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Mozilla Thunderbird File Attachment Spoofing Vulnerability
Solution:
Mozilla Thunderbird 1.5 has been released to address this issue.
Mandriva has released advisory MDKSA-2006:021, along with fixes to address this issue. Please see the referenced advisory for further information.
Mozilla Thunderbird 1.0
Mozilla Thunderbird 1.0.1
Mozilla Thunderbird 1.0.2
Mozilla Thunderbird 1.0.5
Mozilla Thunderbird 1.0.6
Mozilla Thunderbird 1.0.7
Mozilla Thunderbird 1.5 beta 2
Solution:
Mozilla Thunderbird 1.5 has been released to address this issue.
Mandriva has released advisory MDKSA-2006:021, along with fixes to address this issue. Please see the referenced advisory for further information.
Mozilla Thunderbird 1.0
-
Mozilla Thunderbird 1.5.x
http://www.mozilla.com/thunderbird/
Mozilla Thunderbird 1.0.1
-
Mozilla Thunderbird 1.5.x
http://www.mozilla.com/thunderbird/
Mozilla Thunderbird 1.0.2
-
Mozilla Thunderbird 1.5.x
http://www.mozilla.com/thunderbird/
Mozilla Thunderbird 1.0.5
-
Mozilla Thunderbird 1.5.x
http://www.mozilla.com/thunderbird/
Mozilla Thunderbird 1.0.6
-
Mozilla Thunderbird 1.5.x
http://www.mozilla.com/thunderbird/
Mozilla Thunderbird 1.0.7
-
Mozilla Thunderbird 1.5.x
http://www.mozilla.com/thunderbird/
Mozilla Thunderbird 1.5 beta 2
-
Mozilla Thunderbird 1.5.x
http://www.mozilla.com/thunderbird/
References
Mozilla Thunderbird File Attachment Spoofing Vulnerability
References:
References:
- Cisco NX-OS Download Page (Cisco)
- Mozilla Thunderbird Attachment Spoofing Vulnerability (Secunia Research
)