You are here: Known Vulnerabilities in Mozilla Products (Thunderbird 1.0) > MFSA 2005-11

Mozilla Foundation Security Advisory 2005-11

Title: Mail responds to cookie requests
Severity: High
Reporter: Michiel van Leeuwen

Fixed in: Thunderbird 1.0
  Mozilla Suite 1.7.5

Vulnerable: Thunderbird 0.6 - 0.9
  Mozilla Suite 1.7 - 1.7.3

Description

Mozilla mail clients from March to December 2004 responded to cookie requests accompanying content loaded over HTTP, ignoring the setting of the preference "network.cookie.disableCookieForMailNews" (disabled cookies are the default in mail).

Cookies in mail (for example, spam) could be used to track people.

Workaround

Set the mail client not to load remote content at all (the default setting in Thunderbird, the "View as Simple text" option in the Mozilla Suite). Upgrade to the fixed version

References

https://bugzilla.mozilla.org/show_bug.cgi?id=268107