Mozilla Foundation Security Advisory 2009-33

Crash viewing multipart/alternative message with text/enhanced part

Announced
June 22, 2009
Reporter
Bernd Jendrissek
Impact
High
Products
SeaMonkey, Thunderbird
Fixed in
  • SeaMonkey 1.1.17
  • Thunderbird 2.0.0.22

Description

Bernd Jendrissek reported a crash in Thunderbird when viewing a multipart/alternative mail message with a text/enhanced part. Internally this led to operations on an unexpected type of object resulting in a crash which may be exploitable.

References