12th February Comments

Thunderbird security woes

Posted on February 12th, 2008 at 5:44 am

When Firefox 2.12 came out on Feb. 7, it brought with it fixes for three critical security holes and seven that were not quite so serious. According to the security advisories, many of these problems were also fixed in the Thunderbird 2.12 e-mail client. Unfortunately, there is no Thunderbird 2.12.

The Mozilla Foundation’s press release focused on the Firefox 2.12 security fixes. The Foundation also reported, though, in its MFSA (Mozilla Foundation Security Advisory), that these same bugs had been fixed in the fictitious Thunderbird 2.12.

Specifically, the following critical security advisories were reported to be fixed in both Firefox and Thunderbird 2.12: MFSA 2008-01 (crashes with evidence of memory corruption) and MFSA 2008-03 (privilege escalation, XSS, remote code execution). In addition, the serious security bug MFSA 2008-05 (directory traversal via chrome: URI) and moderate security bug MFSA 2008-08 (file action dialog tampering) are reported to have been fixed in the nonexistent Thunderbird 2.12.

Read the Rest

Leave a Reply

You must be logged in to post a comment.