Thunderbird 9.x Multiple Vulnerabilities (Mac OS X)

high Nessus Plugin ID 57775

Synopsis

The remote Mac OS X host contains an email client that is potentially affected by several vulnerabilities.

Description

The installed version of Thunderbird 9.x is potentially affected by the following security issues :

- A use-after-free error exists related to removed nsDOMAttribute child nodes.(CVE-2011-3659)

- Various memory safety issues exist. (CVE-2012-0442, CVE-2012-0443)

- Memory corruption errors exist related to the decoding of Ogg Vorbis files and processing of malformed XSLT stylesheets. (CVE-2012-0444, CVE-2012-0449)

- The HTML5 frame navigation policy can be violated by allowing an attacker to replace a sub-frame in another domain's document. (CVE-2012-0445)

- Scripts in frames are able to bypass security restrictions in XPConnect. This bypass can allow malicious websites to carry out cross-site scripting attacks. (CVE-2012-0446)

- An information disclosure issue exists when uninitialized memory is used as padding when encoding icon images. (CVE-2012-0447)

Solution

Upgrade to Thunderbird 10.0 or later.

See Also

http://dev.w3.org/html5/spec/browsers.html#security-nav

https://www.mozilla.org/en-US/security/advisories/mfsa2012-01/

https://www.mozilla.org/en-US/security/advisories/mfsa2012-03/

https://www.mozilla.org/en-US/security/advisories/mfsa2012-04/

https://www.mozilla.org/en-US/security/advisories/mfsa2012-05/

https://www.mozilla.org/en-US/security/advisories/mfsa2012-06/

https://www.mozilla.org/en-US/security/advisories/mfsa2012-07/

https://www.mozilla.org/en-US/security/advisories/mfsa2012-08/

Plugin Details

Severity: High

ID: 57775

File Name: macosx_thunderbird_10_0.nasl

Version: 1.21

Type: local

Agent: macosx

Published: 2/1/2012

Updated: 7/14/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.0

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:mozilla:thunderbird

Required KB Items: MacOSX/Thunderbird/Installed

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/31/2012

Vulnerability Publication Date: 1/31/2012

Exploitable With

CANVAS (White_Phosphorus)

Metasploit (Firefox 8/9 AttributeChildRemoved() Use-After-Free)

Reference Information

CVE: CVE-2011-3659, CVE-2012-0442, CVE-2012-0443, CVE-2012-0444, CVE-2012-0445, CVE-2012-0446, CVE-2012-0447, CVE-2012-0449

BID: 51752, 51753, 51754, 51755, 51756, 51757, 51765

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990