Mozilla Thunderbird Memory Corruption Vulnerabilities

Posted on Friday, October 19, 2007 @ 23:55:59 CDT in Security
by Raven

SECUNIA ADVISORY ID: SA27313

VERIFY ADVISORY: http://secunia.com/advisories/27313/

CRITICAL: Highly critical

IMPACT: DoS, System access

WHERE: >From remote

SOFTWARE: Mozilla Thunderbird 2.x - http://secunia.com/product/14070/

DESCRIPTION: Some vulnerabilities have been reported in Mozilla Thunderbird, which potentially can be exploited by malicious people to compromise a user's system. For more information see vulnerabilities #1 and #2 in: SA27311

SOLUTION: The vulnerabilities will be fixed in the upcoming version 2.0.0.8.
NOTE: Additional fixes have been added to prevent the exploitation of a URI handling vulnerability in Microsoft Windows.

For more information: SA26201

ORIGINAL ADVISORY: Mozilla Foundation: - http://www.mozilla.org/security/announce/2007/mfsa2007-29.html

OTHER REFERENCES: SA27311: - http://secunia.com/advisories/27311/