Vulnerability Description
The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authentication information without detection via a man-in-the-middle (MITM) attack that bypasses TLS authentication or downgrades CRAM-MD5 authentication to plain authentication.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Thunderbird | 1.0.5 |
References
- http://marc.info/?l=bugtraq&m=113028017608146&w=2
- http://marc.info/?l=bugtraq&m=113034421329653&w=2
- http://www.securityfocus.com/bid/15106
- https://bugzilla.mozilla.org/show_bug.cgi?id=311657
- http://marc.info/?l=bugtraq&m=113028017608146&w=2
- http://marc.info/?l=bugtraq&m=113034421329653&w=2
- http://www.securityfocus.com/bid/15106
- https://bugzilla.mozilla.org/show_bug.cgi?id=311657
FAQ
What is CVE-2005-3402?
CVE-2005-3402 is a vulnerability with a CVSS score of 2.6 (LOW). The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to...
How severe is CVE-2005-3402?
CVE-2005-3402 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-3402?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Thunderbird.