Vulnerability Name: CVE-2010-0161 (CCN-56992) Assigned: 2010-03-16 Published: 2010-03-16 Updated: 2017-09-19 Summary: The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 on Windows Vista, Windows Server 2008 R2, and Windows 7 allows remote SMTP, IMAP, and POP servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via crafted data in a session that uses SSPI. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Low
CVSS v2 Severity: 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P )3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P )3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
Vulnerability Type: CWE-399 Vulnerability Consequences: Denial of Service References: Source: CCN Type: Sun Security BlogMultiple Vulnerabilities in Mozilla Thunderbird Source: MITRE Type: CNACVE-2010-0161 Source: SUSE Type: UNKNOWNSUSE-SR:2010:013 Source: CCN Type: SA39001Mozilla SeaMonkey Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory39001 Source: CCN Type: SA42581Oracle Solaris Thunderbird Multiple Vulnerabilities Source: CCN Type: MFSA 2010-07Fixes for potentially exploitable crashes ported to the legacy branch Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www.mozilla.org/security/announce/2010/mfsa2010-07.html Source: CCN Type: OSVDB ID: 63262Mozilla Multiple Products on Windows extensions/auth/nsAuthSSPI.cpp nsAuthSSPI::Unwrap Function DoS Source: BID Type: UNKNOWN38831 Source: CCN Type: BID-38831Mozilla Thunderbird Multiple Denial of Service Vulnerabilities Source: VUPEN Type: Patch, Vendor AdvisoryADV-2010-0648 Source: CONFIRM Type: Patchhttps://bugzilla.mozilla.org/show_bug.cgi?id=511806 Source: XF Type: UNKNOWNthunderbird-activedirectory-dos(56992) Source: XF Type: UNKNOWNthunderbird-activedirectory-dos(56992) Source: OVAL Type: UNKNOWNoval:org.mitre.oval:def:14159 Source: SUSE Type: SUSE-SR:2010:013SUSE Security Summary Report Vulnerable Configuration: Configuration 1 :cpe:/a:mozilla:thunderbird:0.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:0.2:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:0.3:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:0.4:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:0.5:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:0.6:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:0.7:-:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:0.7.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:0.7.2:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:0.7.3:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:0.8:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:0.9:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.0:-:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.0.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.0.2:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.0.3:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.0.4:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.0.5:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.0.6:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.0.7:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.0.8:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5:-:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5:beta2:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5.0.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5.0.2:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5.0.3:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5.0.4:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5.0.5:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5.0.6:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5.0.7:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5.0.8:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5.0.9:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5.0.10:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5.0.11:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5.0.12:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5.0.13:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5.0.14:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:1.5.2:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.0:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.4:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.5:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.6:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.7:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.8:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.9:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.12:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.14:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.16:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.17:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.18:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.19:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.21:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.22:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:*:*:*:*:*:*:*:* (Version <= 2.0.0.23) Configuration 2 :cpe:/a:mozilla:seamonkey:1.0:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.0:alpha:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.0.3:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.0.4:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.0.5:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.0.6:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.0.7:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.0.8:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.0.9:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1:alpha:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1:beta:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.2:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.3:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.4:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.5:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.6:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.7:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.8:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.9:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.10:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.11:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.12:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.13:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.14:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.15:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.16:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.17:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:*:*:*:*:*:*:*:* (Version <= 1.1.18) AND cpe:/o:microsoft:windows_7:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_vista:*:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:mozilla:thunderbird:2.0.0.2:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.11:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.12:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.13:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.10:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.11:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.14:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.16:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.15:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.12:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.17:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.13:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.18:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.19:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.20:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.14:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.15:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.21:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.16:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.17:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.23:*:*:*:*:*:*:* OR cpe:/a:mozilla:thunderbird:2.0.0.22:*:*:*:*:*:*:* OR cpe:/a:mozilla:seamonkey:1.1.18:*:*:*:*:*:*:* AND cpe:/o:sun:solaris:10::64bit:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2008.0::x86-64:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:* OR cpe:/o:mandriva:linux:2009.0:*:*:*:*:*:*:* OR cpe:/o:mandriva:linux:2009.0:-:x86_64:*:*:*:*:* OR cpe:/o:mandriva:linux:2009.1:*:*:*:*:*:*:* OR cpe:/o:mandriva:linux:2009.1:*:*:*:x86_64:*:*:* OR cpe:/o:mandriva:linux:2010:*:*:*:x86_64:*:*:* OR cpe:/o:mandriva:linux:2010:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions Definition ID Class Title Last Modified oval:org.opensuse.security:def:20100161 V CVE-2010-0161 2015-11-16 oval:org.mitre.oval:def:14159 V The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 on Windows Vista, Windows Server 2008 R2, and Windows 7 allows remote SMTP, IMAP, and POP servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via crafted data in a session that uses SSPI. 2014-10-06
BACK
mozilla thunderbird 0.1
mozilla thunderbird 0.2
mozilla thunderbird 0.3
mozilla thunderbird 0.4
mozilla thunderbird 0.5
mozilla thunderbird 0.6
mozilla thunderbird 0.7
mozilla thunderbird 0.7.1
mozilla thunderbird 0.7.2
mozilla thunderbird 0.7.3
mozilla thunderbird 0.8
mozilla thunderbird 0.9
mozilla thunderbird 1.0
mozilla thunderbird 1.0.1
mozilla thunderbird 1.0.2
mozilla thunderbird 1.0.3
mozilla thunderbird 1.0.4
mozilla thunderbird 1.0.5
mozilla thunderbird 1.0.6
mozilla thunderbird 1.0.7
mozilla thunderbird 1.0.8
mozilla thunderbird 1.5
mozilla thunderbird 1.5 beta2
mozilla thunderbird 1.5.0.1
mozilla thunderbird 1.5.0.2
mozilla thunderbird 1.5.0.3
mozilla thunderbird 1.5.0.4
mozilla thunderbird 1.5.0.5
mozilla thunderbird 1.5.0.6
mozilla thunderbird 1.5.0.7
mozilla thunderbird 1.5.0.8
mozilla thunderbird 1.5.0.9
mozilla thunderbird 1.5.0.10
mozilla thunderbird 1.5.0.11
mozilla thunderbird 1.5.0.12
mozilla thunderbird 1.5.0.13
mozilla thunderbird 1.5.0.14
mozilla thunderbird 1.5.1
mozilla thunderbird 1.5.2
mozilla thunderbird 2.0.0.0
mozilla thunderbird 2.0.0.4
mozilla thunderbird 2.0.0.5
mozilla thunderbird 2.0.0.6
mozilla thunderbird 2.0.0.7
mozilla thunderbird 2.0.0.8
mozilla thunderbird 2.0.0.9
mozilla thunderbird 2.0.0.12
mozilla thunderbird 2.0.0.14
mozilla thunderbird 2.0.0.16
mozilla thunderbird 2.0.0.17
mozilla thunderbird 2.0.0.18
mozilla thunderbird 2.0.0.19
mozilla thunderbird 2.0.0.21
mozilla thunderbird 2.0.0.22
mozilla thunderbird *
mozilla seamonkey 1.0
mozilla seamonkey 1.0 alpha
mozilla seamonkey 1.0 beta
mozilla seamonkey 1.0.1
mozilla seamonkey 1.0.2
mozilla seamonkey 1.0.3
mozilla seamonkey 1.0.4
mozilla seamonkey 1.0.5
mozilla seamonkey 1.0.6
mozilla seamonkey 1.0.7
mozilla seamonkey 1.0.8
mozilla seamonkey 1.0.9
mozilla seamonkey 1.1
mozilla seamonkey 1.1 alpha
mozilla seamonkey 1.1 beta
mozilla seamonkey 1.1.1
mozilla seamonkey 1.1.2
mozilla seamonkey 1.1.3
mozilla seamonkey 1.1.4
mozilla seamonkey 1.1.5
mozilla seamonkey 1.1.6
mozilla seamonkey 1.1.7
mozilla seamonkey 1.1.8
mozilla seamonkey 1.1.9
mozilla seamonkey 1.1.10
mozilla seamonkey 1.1.11
mozilla seamonkey 1.1.12
mozilla seamonkey 1.1.13
mozilla seamonkey 1.1.14
mozilla seamonkey 1.1.15
mozilla seamonkey 1.1.16
mozilla seamonkey 1.1.17
mozilla seamonkey *
microsoft windows 7 *
microsoft windows server 2008 -
microsoft windows vista *
mozilla thunderbird 2.0.0.2
mozilla thunderbird 2.0.0.1
mozilla seamonkey 1.1.1
mozilla thunderbird 2.0.0.11
mozilla thunderbird 2.0.0.12
mozilla thunderbird 2.0.0.13
mozilla seamonkey 1.1.10
mozilla seamonkey 1.1.11
mozilla thunderbird 2.0.0.14
mozilla thunderbird 2.0.0.16
mozilla thunderbird 2.0.0.15
mozilla seamonkey 1.1.12
mozilla thunderbird 2.0.0.17
mozilla seamonkey 1.1.13
mozilla thunderbird 2.0.0.18
mozilla thunderbird 2.0.0.19
mozilla thunderbird 2.0.0.20
mozilla seamonkey 1.1.14
mozilla seamonkey 1.1.15
mozilla thunderbird 2.0.0.21
mozilla seamonkey 1.1.16
mozilla seamonkey 1.1.17
mozilla thunderbird 2.0.0.23
mozilla thunderbird 2.0.0.22
mozilla seamonkey 1.1.18
sun solaris 10
mandrakesoft mandrake linux 2008.0
mandrakesoft mandrake linux 2008.0
mandriva linux 2009.0
mandriva linux 2009.0 -
mandriva linux 2009.1
mandriva linux 2009.1
mandriva linux 2010
mandriva linux 2010