NASLDB: Mozilla Thunderbird 3.1 < 3.1.12 Multiple Vulnerabilities
General
ID: 55886
Name: Mozilla Thunderbird 3.1 < 3.1.12 Multiple Vulnerabilities
Summary: Checks version of Thunderbird
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
CVSS Temporal Vector: CVSS2#E:U/RL:OF/RC:C
Port: –
Family: Windows
Type: Local
Description
The installed version of Thunderbird 3.1 is earlier than 3.1.12. As
such, it is potentially affected by the following security issues :
– Several memory safety bugs exist in the browser engine
that may permit remote code execution. (CVE-2011-2982)
– A dangling pointer vulnerability exists in an SVG text
manipulation routine. (CVE-2011-0084)
– A dangling pointer vulnerability exists in appendChild,
which did not correctly account for DOM objects it
operated upon. (CVE-2011-2378)
– A privilege escalation vulnerability in the event
management code could permit JavaScript to be run in the
wrong context. (CVE-2011-2981)
– A privilege escalation vulnerability exists if a web page
registered for drop events and a browser tab element was
dropped into the content area. (CVE-2011-2984)
– A binary planting vulnerability in
ThinkPadSensor::Startup could permit loading a
malicious DLL into the running process. (CVE-2011-2980)
– A data leakage vulnerability triggered when RegExp.input
was set could allow data from other domains to be read.
(CVE-2011-2983)
Exploiting
Exploit Available: False
Exploitability Ease: No known exploits are available
Sources
CVE: CVE-2011-0084
OSVDB: –
Bugtraq: 49213
scipID: –
Timeline
Vulnerability Disclosure: 2011/08/16
Patch Release: 2011/08/16
Plugin Release: 2011/08/17
Plugin
Version: 1.5
Filename: mozilla_thunderbird_3112.nasl
Filesize: 3596 bytes
MD5 Hash: 1cecf00f3e8d0e598bdcf1438497fc7b
Identification: SMB/transport
Require Keys: Mozilla/Thunderbird/Version
Dependencies: "mozilla_org_installed.nasl"
Copyright: This script is Copyright© 2011 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













