PT-2006-2082 · Mozilla+1 · Thunderbird+1

Crashfr

·

Published

2006-03-07

·

Updated

2018-10-18

·

CVE-2006-1045

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Thunderbird version 1.5
Description The issue concerns the HTML rendering engine in Mozilla Thunderbird. When the "Block loading of remote images in mail messages" option is enabled, it fails to properly block external images from inline HTML attachments. This could allow remote attackers to obtain sensitive information, such as the application version or IP address, when the user reads the email and the external image is accessed.
Recommendations For Mozilla Thunderbird version 1.5, consider disabling the HTML rendering engine for mail messages or avoid reading emails with inline HTML attachments until a fix is available. As a temporary workaround, disable the loading of remote images in mail messages to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1045
DSA-1046-1
DSA-1051-1
RHSA-2006:0330
RHSA-2006_0330

Affected Products

Thunderbird
Red Hat