Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail messages.
Link | Tags |
---|---|
http://www.redhat.com/support/errata/RHSA-2005-323.html | patch vendor advisory |
http://www.securityfocus.com/bid/12407 | vdb entry |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100047 | vdb entry signature |
http://www.redhat.com/support/errata/RHSA-2005-335.html | patch vendor advisory |
http://secunia.com/advisories/19823 | third party advisory |
http://www.mozilla.org/security/announce/mfsa2005-11.html | patch vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=268107 | patch vendor advisory |
http://www.redhat.com/support/errata/RHSA-2005-094.html | patch vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11407 | vdb entry signature |
http://www.novell.com/linux/security/advisories/2006_04_25.html | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/19172 | vdb entry |