Rapid7 Vulnerability & Exploit Database

MFSA2005-11 Thunderbird: Mail responds to cookie requests

Back to Search

MFSA2005-11 Thunderbird: Mail responds to cookie requests

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
11/21/2013
Created
07/25/2018
Added
11/21/2013
Modified
01/30/2015

Description

Mozilla mail clients from March to December 2004 responded to cookie requests accompanying content loaded over HTTP, ignoring the setting of the preference "network.cookie.disableCookieForMailNews" (disabled cookies are the default in mail).Cookies in mail (for example, spam) could be used to track people.

Solution(s)

  • mozilla-thunderbird-upgrade-1_0

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;