Welcome Guest. | Log In| Register | Membership Benefits

  • Email this page E-mail
  • |  Print Print
  • |   Bookmark and Share
  • icon

Thunderbird E-Mail Suffers Similar Security Problem As Firefox


A bug -- like the one disclosed Tuesday in the Linux edition of Firefox -- relates to how the software processes URLs. It was rated as "extremely critical" by a security vendor.



Mozilla Corp.'s Thunderbird e-mail client for Linux suffers from the same serious vulnerability as its Firefox browser, a security firm said Thursday. The difference: Thunderbird has not been patched.

Secunia, a Danish vulnerability tracking vendor, rated the bug -- which like the one disclosed Tuesday in the Linux edition of Firefox, relates to how the software processes URLs -- as "Extremely critical," the company's most dire warning.

The bug is in Thunderbird's parsing of URLs supplied on the command line, if, for instance, a user is tricked into clicking on a "mailto:" link within a browser which uses Thunderbird as its default e-mail client (as Firefox does). Any Linux commands enclosed in backticks are executed.

Although the bug has been reported, and according to Bugzilla, Mozilla's software- and bug-management center, a fix is underway, there is as yet no official patch or updated version of Thunderbird.

Secunia's only recommendation was a terse "Do not use Thunderbird as the default mail handler."

Only the Linux/Unix version of Thunderbird is at risk.


Subscribe to RSS


Advertisement






Get InformationWeek in Print

Apply for a free 52-week subscription to InformationWeek (a $199 value)



NOTE: Offer valid for U.S., U.S. possessions, & Canada only.