Mozilla Thunderbird/Seamonkey Rich Text Integer Overflow Vulnerability

Thunderbird and Seamonkey are prone to an integer-overflow vulnerability because they fail to handle excessively large specially formatted email messages.

A remote attacker can exploit this issue to execute arbitrary code; failed exploit attempts will likely result in denial-of-service conditions.

This issue affects Thunderbird versions prior to 1.5.0.10 and Seamonkey versions prior to 1.0.8.


 

Privacy Statement
Copyright 2010, SecurityFocus