NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security

Security


Thunderbird Is Also Vulnerable

Multiple flaws discovered in the e-mail client

By Bogdan Popa, Security and Search Engines Editor

20th of December 2006, 07:56 GMT

Adjust text size:


Mozilla Thunderbird is one of the most popular e-mail clients, many users choosing it in the detriment of Microsoft's products, Outlook Express. Besides the main function that allows users to send and receive e-mail messages, Thunderbird offers more functionality with its support for extensions, tiny programs that add more features to the application.

Today, Mozilla posted an advisory to say that the company discovered multiple vulnerabilities in the e-mail client that can allow an attacker to compromise an affected system.

Security
company Secunia also released a security notice to inform users about the Thunderbird vulnerability, rating the flaw as highly critical.

"A boundary error within the processing of mail headers can be exploited to cause a heap-based buffer overflow via an overly long "Content-Type" header in an external message body.
A boundary error within the processing of rfc2047-encoded headers can be exploited to cause a heap-based buffer overflow," Secunia said in the advisory.

"Georgi Guninski reported that long Content-Type headers in external message bodies could cause a heap buffer overflow when processing mail headers. While working on that code David Bienvenu discovered a similar overflow could occur when processing long rfc2047-encoded headers. Either overflow could be exploited to execute arbitrary code," Mozilla added.

The Firefox developer also mentioned that SeaMonkey 1.0.7 is also vulnerable to attacks, saying that the solution is to update to the latest versions of the affected applications. Secunia completed this statement adding that the affected versions of Thunderbird are 1.0.x and 1.5.x.

Mozilla Thunderbird and SeaMonkey were both tested by Softpedia and are available as a free download HERE and HERE.
Read by 711 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.6/5) 9 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


The updated Mozilla is safer

Multiple flaws in Mozilla

Mozilla Unveils Firefox 3.0 Gran Paradiso

The Beta Version of Thunderbird 2 Has Arrived!

Firefox Multiple Vulnerabilities!

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM