Mozilla Thunderbird < 2.0.0.14 Multiple Vulnerabilities

high Log Correlation Engine Plugin ID 801277

Synopsis

The remote Windows host contains a mail client that is affected by multiple vulnerabilities.

Description

The installed version of Thunderbird is affected by various security issues :

- A series of vulnerabilities that allow for JavaScript privilege escalation and arbitrary code execution.
- Several stability bugs leading to crashes that, in some cases, show traces of memory corruption.

Solution

Upgrade to version 2.0.0.14 or higher.

See Also

http://.mozilla.org/security/announce/2008/mfsa2008-15.html

http://.mozilla.org/security/announce/2008/mfsa2008-14.html

Plugin Details

Severity: High

ID: 801277

Family: SMTP Clients

Nessus ID: 32134

Risk Information

CVSS v2

Risk Factor: High

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Reference Information

CVE: CVE-2008-1233, CVE-2008-1234, CVE-2008-1235, CVE-2008-1236, CVE-2008-1237