The Wysiwyg Rendering Engine ("rich Mail" Edito vulnerability report
vulnerabilities.aspcode.net
Phase:
The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.
References
BUGTRAQ:Wednesday, February 22, 2006 Mozilla Thunderbird : Remote Code Execution & Denial of Service | URL:http://www.securityfocus.com/archive/1/archive/1/425786/100/0/threaded | CONFIRM:http://www.mozilla.org/security/announce/2006/mfsa2006-21.html | CONFIRM:ht
Votes:
Assigned (Friday, February 24, 2006)
Comments:
None (candidate not yet proposed)
F7:
Tagged as
rendering
WYSIWYG
engine