Lucene search

K
ubuntuUbuntuUSN-469-1
HistoryJun 06, 2007 - 12:00 a.m.

Thunderbird vulnerabilities

2007-06-0600:00:00
ubuntu.com
59

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7

Confidence

Low

EPSS

0.969

Percentile

99.7%

Releases

  • Ubuntu 7.04
  • Ubuntu 6.10
  • Ubuntu 6.06

Details

Gaëtan Leurent showed a weakness in APOP authentication. An attacker
posing as a trusted server could recover portions of the user’s
password via multiple authentication attempts. (CVE-2007-1558)

Various flaws were discovered in the layout and JavaScript engines. By
tricking a user into opening a malicious email, an attacker could execute
arbitrary code with the user’s privileges. Please note that JavaScript
is disabled by default for emails, and it is not recommended to enable
it. (CVE-2007-2867, CVE-2007-2868)

OSVersionArchitecturePackageVersionFilename
Ubuntu7.04noarchmozilla-thunderbird< 1.5.0.12-0ubuntu0.7.04UNKNOWN
Ubuntu6.10noarchmozilla-thunderbird< 1.5.0.12-0ubuntu0.6.10UNKNOWN
Ubuntu6.06noarchmozilla-thunderbird< 1.5.0.12-0ubuntu0.6.06UNKNOWN

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7

Confidence

Low

EPSS

0.969

Percentile

99.7%