Mozilla Thunderbird Multiple Remote Information Disclosure Vulnerabilities
BID:16881
Info
Mozilla Thunderbird Multiple Remote Information Disclosure Vulnerabilities
| Bugtraq ID: | 16881 |
| Class: | Design Error |
| CVE: |
CVE-2006-1045 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2006 12:00AM |
| Updated: | Sep 05 2007 02:12AM |
| Credit: | <[email protected]> discovered these issues. |
| Vulnerable: |
S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 Redhat Fedora Core3 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 Mozilla Thunderbird 1.5 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 HP HP-UX B.11.11 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
Mozilla Thunderbird Multiple Remote Information Disclosure Vulnerabilities
Mozilla Thunderbird is susceptible to multiple remote information-disclosure vulnerabilities. These issues are due to the application's failure to properly enforce the restriction for downloading remote content in email messages.
These issues allow remote attackers to gain access to potentially sensitive information, aiding them in further attacks. Attackers may also exploit these issues to know whether and when users read email messages.
Mozilla Thunderbird version 1.5 is vulnerable to these issues; other versions may also be affected.
Mozilla Thunderbird is susceptible to multiple remote information-disclosure vulnerabilities. These issues are due to the application's failure to properly enforce the restriction for downloading remote content in email messages.
These issues allow remote attackers to gain access to potentially sensitive information, aiding them in further attacks. Attackers may also exploit these issues to know whether and when users read email messages.
Mozilla Thunderbird version 1.5 is vulnerable to these issues; other versions may also be affected.
Exploit / POC
Mozilla Thunderbird Multiple Remote Information Disclosure Vulnerabilities
An exploit is not required to trigger these issues. Attackers will likely use SMTP software to exploit these issues.
The referenced message from Renaud Lifchitz <[email protected]> contains a sample email message provided by <[email protected]>. The base64 encoded data directs affected applications to download content from 'http://www.sysdream.com' and 'http://www.sysdream.com/test.css'.
Symantec cannot vouch for the validity or safety of third-party websites.
An exploit is not required to trigger these issues. Attackers will likely use SMTP software to exploit these issues.
The referenced message from Renaud Lifchitz <[email protected]> contains a sample email message provided by <[email protected]>. The base64 encoded data directs affected applications to download content from 'http://www.sysdream.com' and 'http://www.sysdream.com/test.css'.
Symantec cannot vouch for the validity or safety of third-party websites.
Solution / Fix
Mozilla Thunderbird Multiple Remote Information Disclosure Vulnerabilities
Solution:
Please see the references for more information.
S.u.S.E. Linux Professional 10.0
S.u.S.E. Linux Professional 9.1
S.u.S.E. Linux Professional 9.2
S.u.S.E. Linux Professional 9.3
Solution:
Please see the references for more information.
S.u.S.E. Linux Professional 10.0
-
SuSE MozillaFirefox-1.0.8-0.2.ppc.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/MozillaFirefox-1. 0.8-0.2.ppc.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/MozillaThunderbi rd-1.0.8-0.2.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.x86_64.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/MozillaThunder bird-1.0.8-0.2.x86_64.rpm
S.u.S.E. Linux Professional 9.1
-
SuSE MozillaThunderbird-1.0.8-0.1.i586.rpm
SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/MozillaThunderbir d-1.0.8-0.1.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.1.x86_64.rpm
SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/MozillaThunde rbird-1.0.8-0.1.x86_64.rpm
S.u.S.E. Linux Professional 9.2
-
SuSE MozillaThunderbird-1.0.8-0.2.i586.rpm
SUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/MozillaThunderbir d-1.0.8-0.2.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.x86_64.rpm
SUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/MozillaThunderb ird-1.0.8-0.2.x86_64.rpm
S.u.S.E. Linux Professional 9.3
-
SuSE MozillaThunderbird-1.0.8-0.2.i586.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/MozillaThunderbir d-1.0.8-0.2.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.x86_64.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/MozillaThunderb ird-1.0.8-0.2.x86_64.rpm
References
Mozilla Thunderbird Multiple Remote Information Disclosure Vulnerabilities
References:
References:
- Cisco NX-OS Download Page (Cisco)
- HPSBUX02156 SSRT061236 rev.1 - HP-UX Running Thunderbird, Remote Unauthorized Ac (Hewlett-Packard )
- RHSA-2006:0330-10 - thunderbird security update (RedHat)
- Mozilla Thunderbird : Multiple Information Disclosure Vulnerabilities (Renaud Lifchitz
) - Re: Mozilla Thunderbird : Multiple Information Disclosure Vulnerabilities (Steve Shockley
) - HPSBUX02156 SSRT061236 rev.2 - HP-UX Running (HP)
- HPSBUX02156 SSRT061236 rev.3 - HP-UX Running Thunderbird, Remote Unauthorized Ac (HP)