Mozilla Foundation Security Advisory 2005-11

Mail responds to cookie requests

Announced
January 21, 2005
Reporter
Michiel van Leeuwen
Impact
High
Products
Mozilla Suite, Thunderbird
Fixed in
  • Mozilla Suite 1.7.5
  • Thunderbird 1
Vulnerable
  • Thunderbird 0.6 - 0.9
  • Mozilla Suite 1.7 - 1.7.3

Description

Mozilla mail clients from March to December 2004 responded to cookie requests accompanying content loaded over HTTP, ignoring the setting of the preference "network.cookie.disableCookieForMailNews" (disabled cookies are the default in mail).

Cookies in mail (for example, spam) could be used to track people.

Workaround

Set the mail client not to load remote content at all (the default setting in Thunderbird, the "View as Simple text" option in the Mozilla Suite). Upgrade to the fixed version

References

https://bugzilla.mozilla.org/show_bug.cgi?id=268107