Oval Definition:oval:org.mitre.oval:def:23741
Revision Date:2014-05-26Version:56
Title:ELSA-2011:0886: thunderbird security update (Critical)
Description:CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a JavaScript "document.cookie =" expression, a different vulnerability than CVE-2011-2374.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2011-0083
CVE-2011-0085
CVE-2011-2362
CVE-2011-2363
CVE-2011-2364
CVE-2011-2365
CVE-2011-2374
CVE-2011-2375
CVE-2011-2376
CVE-2011-2377
CVE-2011-2605
ELSA-2011:0886-01
Platform(s):Oracle Linux 6
Product(s):thunderbird
Definition Synopsis
  • thunderbird is earlier than 0:3.1.11-2.el6_1
  • AND Oracle Linux 6.x
  • BACK