|
|
|

Code Execution Flaw Haunts Mozilla Thunderbird
By Ryan Naraine
2008-02-27
Article Views: 3839
Article Rating:    / 5
| Rate This Article: |
|
| Add This Article To: |
|
|
The open-source mail client is updated to fix at least six security holes that could expose users to a wide range of malicious attacks.
A new version of the open-source Mozilla Thunderbird mail client has been released to fix at least six security vulnerabilities that could expose users to PC takeover attacks.
The most serious of the six vulnerabilities, a "critical" heap buffer overflow in external MIME bodies, could allow an attacker to execute arbitrary code with the privileges of the current user.
"When calculating the number of bytes to allocate for a heap buffer, sufficient space is not reserved for all of the data being copied into the buffer. This results in up to three bytes of the buffer being overflowed, potentially allowing for the execution of arbitrary code, according to an alert from iDefense, the company that reported the flaw to Mozilla.
Exploitation requires that an attacker social engineer a user into viewing a malicious message in Thunderbird. If the "View->Message Pane" option is turned on (in the "Preview" pane), which is the default, then all a targeted user has to do is select the message in the browsing pane.
Once the message is previewed, the vulnerability will be triggered, iDefense warned.
The flaw affects both Linux and Windows users.
Mozilla also documented a total of five additional issues that could lead for information disclosure, directory traversal, privilege escalation, cross-site scripting and remote code execution attacks.
The Thunderbird update also fixes several mail client crashes with evidence of memory corruption.
The latest Thunderbird update comes on the heels of the launch of Mozilla Messaging, the new mail focused subsidiary of the non-profit Mozilla Foundation
The primary focus of the Mozilla Messaging start-up is the development of Thunderbird 3, which promises integrated calendaring, better search and enhancements to the overall user experience.
|
|
 |
 |
| FEATURED SPONSOR |
NEW Diskeeper 2009 Free Trial
With today's bigger drives and larger files, fragmentation is a bigger problem than ever, causing slowdowns, freeze-ups, and seemingly random crashes. You know that defragmentation solves these problems— that's why you need NEW Diskeeper 2009. It features a host of new technologies that keep your systems running like new.
See for yourself - download and try FREE now! |
|
Sponsored by
| |
|
| |
|
|
MOST READ SECURITY STORIES PAST 7 DAYS
MOST READ SECURITY STORIES PAST 30 DAYS
|
 |
 |
 |
EWEEK E-MAIL NEWSLETTERS bring you reliable, timely
information to stay on top of the business of technology -- and
technology in business -- and get more out of the Web.
Make your choices and start your subscriptions today!
| 
|
 |
EWEEK RSS NEWS FEEDS contain a daily feed of our latest stories from over 30 different categories including Enterprise Apps, Business Intelligence, Security, VOIP and more!
Subscribe to our RSS feeds today for free...
| 
| |
|