FreeBSD Ports: thunderbird

Published: 2008-09-04 18:41:11
CVE Author: NIST National Vulnerability Database

CVSS Base Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Technical Details:
The following Linux Distribution Packages are affected: thunderbird de-linux-mozillafirebird el-linux-mozillafirebird firefox ja-linux-mozillafirebird-gtk1 ja-mozillafirebird-gtk2 linux-mozillafirebird linux-phoenix phoenix ru-linux-mozillafirebird zhCN-linux-mozillafirebird zhTW-linux-mozillafirebird de-netscape7 fr-netscape7 ja-netscape7 netscape7 pt_BR-netscape7 linux-mozilla linux-mozilla-devel mozilla-gtk1 mozilla mozilla+ipv6 mozilla-embedded mozilla-firebird mozilla-gtk mozilla-gtk2 mozilla-thunderbird linux-netscape de-linux-netscape fr-linux-netscape ja-linux-netscape CVE-2004-0904 Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.

Recommendations:
Update your system with the appropriate patches or software upgrades. http://bugzilla.mozilla.org/show_bug.cgi?id=255067 http://www.vuxml.org/freebsd/ab9c559e-115a-11d9-bc4a-000c41e2cdad.html

Summary:
The remote host is missing an update to the system as announced in the referenced advisory.

Detection Type:
Linux Distribution Package

Solution Type:
Vendor Patch

NIST (National Institute of Standards and Technology) NVD (National Vulnerability Database)

https://nvd.nist.gov/vuln/detail/CVE-2004-0904

CVE Analysis

https://www.mageni.net/cve/CVE-2004-0904

SecurityFocus Bugtraq ID:

https://www.securityfocus.com/bid/11171

Severity
High
CVSS Score
10.0
Published
2008-09-04
Modified
2016-10-04
Category
FreeBSD Local Security Checks

You never have to pay for a vulnerability scanning and management software again.

Tired of paying a subscription 'per asset' or 'per IP'? Well you can officially cancel your current subscription. Mageni provides a free, open source and enterprise-ready vulnerability scanning and management platform which helps you to find, prioritize, remediate and manage your vulnerabilities. It is free and always will be.