Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2008:0105

The remote host is missing updates announced in
advisory RHSA-2008:0105.

Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the way Thunderbird processed certain malformed
HTML mail content. A HTML mail message containing malicious content could
cause Thunderbird to crash, or potentially execute arbitrary code as the
user running Thunderbird. (CVE-2008-0412, CVE-2008-0413, CVE-2008-0415,

Several flaws were found in the way Thunderbird displayed malformed HTML
mail content. A HTML mail message containing specially-crafted content
could trick a user into surrendering sensitive information. (CVE-2008-0591,

A flaw was found in the way Thunderbird handles certain chrome URLs. If a
user has certain extensions installed, it could allow a malicious HTML mail
message to steal sensitive session data. Note: this flaw does not affect a
default installation of Thunderbird. (CVE-2008-0418)

Note: JavaScript support is disabled by default in Thunderbird
the above
issues are not exploitable unless JavaScript is enabled.

A flaw was found in the way Thunderbird saves certain text files. If a
remote site offers a file of type plain/text, rather than text/plain,
Thunderbird will not show future text/plain content to the user, forcing
them to save those files locally to view the content. (CVE-2008-0592)

Users of thunderbird are advised to upgrade to these updated packages,
which contain backported patches to resolve these issues.

Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

Risk factor : Critical

CVSS Score:

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-0412
BugTraq ID: 27683
Bugtraq: 20080209 rPSA-2008-0051-1 firefox (Google Search)
Bugtraq: 20080212 FLEA-2008-0001-1 firefox (Google Search)
Bugtraq: 20080229 rPSA-2008-0093-1 thunderbird (Google Search)
Debian Security Information: DSA-1484 (Google Search)
Debian Security Information: DSA-1485 (Google Search)
Debian Security Information: DSA-1489 (Google Search)
Debian Security Information: DSA-1506 (Google Search)
SuSE Security Announcement: SUSE-SA:2008:008 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2008-0413
Common Vulnerability Exposure (CVE) ID: CVE-2008-0415
Common Vulnerability Exposure (CVE) ID: CVE-2008-0418
BugTraq ID: 27406
CERT/CC vulnerability note: VU#309608
Common Vulnerability Exposure (CVE) ID: CVE-2008-0419
CERT/CC vulnerability note: VU#879056
Common Vulnerability Exposure (CVE) ID: CVE-2008-0591
BugTraq ID: 24293
Bugtraq: 20070604 Assorted browser vulnerabilities (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2008-0592
Common Vulnerability Exposure (CVE) ID: CVE-2008-0593
CopyrightCopyright (c) 2008 E-Soft Inc.

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2021 E-Soft Inc. All rights reserved.