Thunderbird < 16.0.1 Multiple Vulnerabilities (Mac OS X)

High Nessus Plugin ID 62587


The remote Mac OS X host contains a mail client that is potentially affected by several vulnerabilities.


The installed version of Thunderbird is earlier than 16.0.1 and is therefore potentially affected by the following security issues :

- An unspecified error related to the WebSockets implementation and the function 'mozilla::net::FailDelayManager::Lookup' can allow application crashes and potentially, arbitrary code execution. (CVE-2012-4191)

- An unspecified error exists that can allow attackers to bypass the 'Same Origin Policy' and access the 'Location' object. (CVE-2012-4192)

- An error exists related to 'security wrappers' and the function 'defaultValue()' that can allow cross-site scripting attacks. (CVE-2012-4193)


Upgrade to Thunderbird 16.0.1 or later.

See Also

Plugin Details

Severity: High

ID: 62587

File Name: macosx_thunderbird_16_0_1.nasl

Version: $Revision: 1.9 $

Type: local

Agent: macosx

Published: 2012/10/17

Modified: 2017/06/06

Dependencies: 56557

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:mozilla:thunderbird

Required KB Items: MacOSX/Thunderbird/Installed

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2012/10/11

Vulnerability Publication Date: 2012/10/10

Reference Information

CVE: CVE-2012-4191, CVE-2012-4192, CVE-2012-4193

BID: 56153, 56154, 56155

OSVDB: 86125, 86126, 86128

CWE: 20, 74, 79, 442, 629, 711, 712, 722, 725, 750, 751, 800, 801, 809, 811, 864, 900, 928, 931, 990