Mozilla · Thunderbird · CVE-2005-0149
**Name of the Vulnerable Software and Affected Versions**
Thunderbird versions 0.6 through 0.9
Mozilla versions 1.7 through 1.7.3
**Description**
The issue allows remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail messages, as the software does not obey the network.cookie.disableCookieForMailNews preference.
**Recommendations**
For Thunderbird versions 0.6 through 0.9, consider disabling the use of cookies in e-mail messages until a patch is available.
For Mozilla versions 1.7 through 1.7.3, restrict access to cookies in e-mail messages to minimize the risk of exploitation.