Mozilla Thunderbird Memory Corruption Vulnerabilities

Posted on Wednesday, February 04, 2009 @ 22:14:35 CST in Security
by Raven

SECUNIA ADVISORY ID: SA33802

VERIFY ADVISORY: http://secunia.com/advisories/33802/

CRITICAL: Highly critical

IMPACT: DoS, System access

SOFTWARE: Mozilla Thunderbird 2.x - http://secunia.com/advisories/product/14070/

DESCRIPTION: Some vulnerabilities have been reported in Mozilla Thunderbird, which can potentially be exploited by malicious people to compromise a user's system. For more information see vulnerabilities #1 and #2 in: SA33799 - The vulnerabilities are reported in versions prior to 2.0.0.21.

SOLUTION: The vulnerabilities will be fixed in an upcoming version 2.0.0.21. The vendor recommends to disable Javascript until an update is available.

ORIGINAL ADVISORY: http://www.mozilla.org/security/announce/2009/mfsa2009-01.html

OTHER REFERENCES: SA33799: http://secunia.com/advisories/33799/