>> Mozilla Thunderbird Attachment Extension and Type Spoofing Vulnerability
Title : Mozilla Thunderbird Attachment Extension and Type Spoofing Vulnerability VUPEN ID : VUPEN/ADV-2006-0230 CVE ID : CVE-2006-0236
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-01-17
Technical Description
A vulnerability has been identified in Mozilla Thunderbird, which could be exploited by remote attackers to trick users into executing a malicious file. This flaw is due to an error when displaying email attachments with specially crafted "Content-Type" headers and overly long filenames, which could be exploited by attackers to spoof file types and extensions and trick users into opening and executing malicious content.