You are currently viewing a snapshot of www.mozilla.org taken on April 21, 2008. Most of this content is highly out of date (some pages haven't been updated since the project began in 1998) and exists for historical purposes only. If there are any pages on this archive site that you think should be added back to www.mozilla.org, please file a bug.



You are here: Known Vulnerabilities in Mozilla Products (Thunderbird 1.0) > MFSA 2005-11

Mozilla Foundation Security Advisory 2005-11

Title: Mail responds to cookie requests
Severity: High
Reporter: Michiel van Leeuwen

Fixed in: Thunderbird 1.0
  Mozilla Suite 1.7.5

Vulnerable: Thunderbird 0.6 - 0.9
  Mozilla Suite 1.7 - 1.7.3

Description

Mozilla mail clients from March to December 2004 responded to cookie requests accompanying content loaded over HTTP, ignoring the setting of the preference "network.cookie.disableCookieForMailNews" (disabled cookies are the default in mail).

Cookies in mail (for example, spam) could be used to track people.

Workaround

Set the mail client not to load remote content at all (the default setting in Thunderbird, the "View as Simple text" option in the Mozilla Suite). Upgrade to the fixed version

References

https://bugzilla.mozilla.org/show_bug.cgi?id=268107