Thunderbird 2.0.0.19 addresses seven security issues

Mozilla on Wednesday updated its email client with the release of Thunderbird 2.0.0.19, which addresses seven flaws – most of which were also fixed in the Firefox browser update 3.0.5 earlier this month.

Five of the flaws were rated “moderate,” and two were rated “low,” out of Mozilla's four-tiered rating scale of critical, high, moderate and low.

Of the moderate bugs:  A vulnerability titled “XSS and JavaScript privilege escalation” involves XBL binding, when attached to an unloaded document, can be used to violate the same-origin policy and execute arbitrary JavaScript within the context of a different website, according to Mozilla's release notes.

The vulnerability titled “cross-domain data theft via script redirect error message” could be used by a malicious website to steal private data from users who are authenticated on the redirected website. The vulnerability titled “XMLHttpRequest 302 response disclosure” could cause potentially sensitive data to be revealed, including URL parameters and content in the response body.

The vulnerability titled “information stealing via loadBindingDocument” could result in XBL bindings being used to read data from other domains, a violation of the same-origin policy, according to Mozilla's release notes. “Crashes with evidence of memory corruption” is the title of a vulnerability that involves stability bugs in the browser engine used in Firefox and other Mozilla-based products. Mozilla said that some of the crashes showed evidence of memory corruption, and it is presumed that some could be exploited to run arbitrary code.



close

Next Article in News

Sign up to our newsletters

More in News

Bitcoin mining botnet has become one of the most prevalent cyber threats

Fortinet researchers have tracked 100,000 new ZeroAccess trojan infections per week, making the botnet very lucrative to its owners.

House Intelligence Committee OKs amended version of controversial CISPA

House Intelligence Committee OKs amended version of controversial ...

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

Judge rules hospital can ask ISP for help ...

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.