Mozilla Thunderbird Malformed MIME Message Denial Of Service Vulnerability
BID:32869
Info
Mozilla Thunderbird Malformed MIME Message Denial Of Service Vulnerability
| Bugtraq ID: | 32869 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-5430 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2008 12:00AM |
| Updated: | Dec 17 2008 11:52PM |
| Credit: | Bernhard 'Bruhns' Brehm at Recurity Labs |
| Vulnerable: |
Mozilla Thunderbird 2.0 .14 |
| Not Vulnerable: | |
Discussion
Mozilla Thunderbird Malformed MIME Message Denial Of Service Vulnerability
Mozilla Thunderbird is prone to a denial-of-service vulnerability because the application fails to properly handle malformed multipart MIME messages.
An attacker can exploit this issue to crash the application during delivery.
Mozilla Thunderbird is prone to a denial-of-service vulnerability because the application fails to properly handle malformed multipart MIME messages.
An attacker can exploit this issue to crash the application during delivery.
Exploit / POC
Mozilla Thunderbird Malformed MIME Message Denial Of Service Vulnerability
An attacker may trigger this issue by constructing a malicious email message and sending it to an unsuspecting victim.
An attacker may trigger this issue by constructing a malicious email message and sending it to an unsuspecting victim.
Solution / Fix
Mozilla Thunderbird Malformed MIME Message Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Mozilla Thunderbird Malformed MIME Message Denial Of Service Vulnerability
References:
References:
- Cisco NX-OS Download Page (Cisco)
- DoS attacks on MIME-capable software via malformed MIME emails (Recurity Labs)
- DoS attacks on MIME-capable software via complex MIME emails ([email protected])
- Re: DoS attacks on MIME-capable software via complex MIME emails ("Vladimir '3APA3A' Dubrovin" <[email protected]>)