CVE Vulnerabilities

CVE-2006-1045

Published: Mar 07, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The HTML rendering engine in Mozilla Thunderbird 1.5, when Block loading of remote images in mail messages is enabled, does not properly block external images from inline HTML attachments, which could allow remote attackers to obtain sensitive information, such as application version or IP address, when the user reads the email and the external image is accessed.

Affected Software

Name Vendor Start Version End Version
Thunderbird Mozilla 1.5 (including) 1.5 (including)
Red Hat Enterprise Linux 4 RedHat thunderbird-0:1.0.8-1.4.1 *
Firefox Ubuntu dapper *
Firefox Ubuntu devel *
Firefox Ubuntu edgy *
Firefox Ubuntu feisty *
Firefox-granparadiso Ubuntu devel *
Lightning-sunbird Ubuntu devel *
Midbrowser Ubuntu devel *
Mozilla-thunderbird Ubuntu dapper *
Mozilla-thunderbird Ubuntu edgy *
Mozilla-thunderbird Ubuntu feisty *
Mozilla-thunderbird Ubuntu upstream *
Xulrunner Ubuntu devel *
Xulrunner Ubuntu edgy *
Xulrunner Ubuntu feisty *

References