Mozilla Thunderbird '.documentURI' and '.textContent' Properties May Let Remote Users Obtain Information
|
|
SecurityTracker Alert ID: 1021247
|
|
SecurityTracker URL: http://securitytracker.com/id?1021247
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Nov 20 2008
|
Impact: Disclosure of user information
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Mozilla Foundation Security Advisory
|
Version(s): prior to 2.0.0.18
|
Description: A vulnerability was reported in Mozilla Thunderbird. A remote user can obtain potentially sensitive information in certain cases.
A remote user can send an e-mail message containing scripting code that, when received by the target user, will access the '.documentURI'
and '.textContent' DOM properties to obtain information from the target user's system. Users with JavaScript enabled in mail are
affected.
SeaMonkey is also affected.
Boris Zbarsky reported this vulnerability.
|
Impact: A remote user can obtain potentially sensitive information in certain cases.
|
Solution: The vendor has issued a fix (2.0.0.18).
The vendor's advisory is available at:
http://www.mozilla.org/security/announce/2008/mfsa2008-59.html
|
Vendor URL: www.mozilla.org/security/announce/2008/mfsa2008-59.html (Links to External Site)
|
Cause: Access control error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Wed, 19 Nov 2008 23:15:24 -0500
Subject: Mozilla Thunderbird
|
http://www.mozilla.org/security/announce/2008/mfsa2008-59.html
|
|