PT-2006-2082 · Mozilla+1 · Thunderbird+1
Crashfr
·
Published
2006-03-07
·
Updated
2018-10-18
·
CVE-2006-1045
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Thunderbird version 1.5
Description
The issue concerns the HTML rendering engine in Mozilla Thunderbird. When the "Block loading of remote images in mail messages" option is enabled, it fails to properly block external images from inline HTML attachments. This could allow remote attackers to obtain sensitive information, such as the application version or IP address, when the user reads the email and the external image is accessed.
Recommendations
For Mozilla Thunderbird version 1.5, consider disabling the HTML rendering engine for mail messages or avoid reading emails with inline HTML attachments until a fix is available. As a temporary workaround, disable the loading of remote images in mail messages to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Thunderbird
Red Hat