Summary
This host is installed with Mozilla Thunderbird ESR and is prone to multiple vulnerabilities.
Impact
Successful exploitation could allow attackers to inject scripts, bypass certain security restrictions, execute arbitrary code in the context of the browser.
Impact Level: System/Application
Solution
Upgrade to Mozilla Thunderbird ESR 10.0.7 or later For updates refer to http://www.mozilla.org/en-US/thunderbird
Insight
- An error in the installer will launch incorrect executable following new installation via a crafted executable file in a root directory.
- An error in the web console can be exploited to inject arbitrary code that will be executed with chrome privileges.
Affected
Mozilla Thunderbird ESR version 10.x before 10.0.7 on Mac OS X
References
Severity
Classification
-
CVE CVE-2012-3980 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Adobe Acrobat Multiple Vulnerabilities-01 Sep14 (Mac OS X)
- Adobe Acrobat Out-of-bounds Vulnerability Feb15 (Windows)
- Adobe Flash Player Arbitrary Code Execution Vulnerability - 01 Feb14 (Linux)
- Adobe AIR Multiple Vulnerabilities-01 Dec13 (Windows)
- Aastra IP Telephone Hardcoded Telnet Password Security Bypass Vulnerability