Securiteam

Welcome to the SecuriTeam RSS Feed - sponsored by Beyond Security. Know Your Vulnerabilities! Visit BeyondSecurity.com for your web site, network and code security audit and scanning needs.

Mozilla Thunderbird : Remote Code Execution & Denial of Service

//----- Advisory


Program          : Mozilla Thunderbird
Homepage         : http://www.mozilla.com/thunderbird/
Tested version   : <= 1.0.7
Found by         : nono2357 at sysdream dot com
This advisory    : nono2357 at sysdream dot com
Discovery date   : 2006/01/28

//----- Application description


Full-Featured Email

Simple to use, powerful, and customizable, Thunderbird is a full-featured
email application. Thunderbird supports IMAP and POP mail protocols, as well
as HTML mail formatting. Easily import your existing email accounts and
messages. Built-in RSS capabilities, powerful quick search, spell check as you
type, global inbox, deleting attachments and advanced message filtering round
out Thunderbird's modern feature set.


//----- Description of vulnerability


Thunderbird's WYSIWYG rendering engine insufficiently filter javascript
scripts. It is possible to write javascript in the SRC attribute of the IFRAME
tag. This lead to execution when the email is edited (for instance when
replying to the email), even if javascript is disabled in the preferences.


//----- Proof Of Concept


* Javascript execution :


<iframe src="javascript:alert('Found by www.sysdream.com !')">


* Denial of service (application crash) :


<iframe src="javascript:parent.document.write('Found by www.sysdream.com !')" />



//----- Solution


Upgrade to version 1.5.

Download page : http://www.mozilla.com/thunderbird/all.html
Direct link : http://ftp.mozilla.org/pub/mozilla.org/thunderbird/releases/1.5/


//----- Impact


Successful exploitation may lead to information disclosure (application
version, platform, user emails, user preferences, ...) or could crash the
application.  


//----- Credits


http://www.sysdream.com
nono2357 at sysdream dot com


//----- Greetings


crashfr & the hackademy ...

<< Mozilla Thunderbird : Multiple Information Disclosure Vulnerabilities | | Connectix Boards: Multiple XSS #2 >>

Liens Relatifs

-->
-->

US-CERT

National Vulnerability Database
This feed contains the most recent fully analyzed CVE cyber vulnerabilities published within the National Vulnerability Database.
  • CVE-2010-0559 (opensolaris)

  • The default configuration of Oracle OpenSolaris snv_91 through snv_131 allows attackers to have an unspecified impact via vectors related to using kclient to join a Windows Active Directory domain.
  • CVE-2010-0558 (opensolaris)

  • The default configuration of Oracle OpenSolaris snv_77 through snv_131 allows attackers to have an unspecified impact via vectors related to using smbadm to join a Windows Active Directory domain.
  • CVE-2010-0557 (cognos_express)

  • IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging hardcoded credentials.
  • CVE-2009-4185 (system_management_homepage)

  • Cross-site scripting (XSS) vulnerability in proxy/smhui/getuiinfo in HP System Management Homepage (SMH) before 6.0 allows remote attackers to inject arbitrary web script or HTML via the servercert parameter.
  • CVE-2009-2752 (websphere_commerce)

  • IBM WebSphere Commerce 7.0 does not properly encrypt data in a database, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms.
  • CVE-2009-2751 (websphere_commerce)

  • IBM WebSphere Commerce 7.0 uses the same cryptographic key for session attributes and merchant data encryption, which has unspecified impact and remote attack vectors.
  • CVE-2003-1587 (loganpro)

  • Cross-site scripting (XSS) vulnerability in LoganPro allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.
  • CVE-2003-1586 (webexpert)

  • Cross-site scripting (XSS) vulnerability in WebExpert allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.
  • CVE-2003-1585 (weblog_expert)

  • Cross-site scripting (XSS) vulnerability in WebLogExpert allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
  • CVE-2003-1584 (surfstats)

  • Cross-site scripting (XSS) vulnerability in SurfStats allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
REFWEO.com
manga chat gastronomie sextv vphone