CVE-2005-2353: Low severity Mozilla Thunderbird vulnerability
Published Aug 5, 2005
·Updated
run-mozilla.sh in Thunderbird, with debugging enabled, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
Affected Software
1 affected component
Mozilla Thunderbird=1.5.0.9
Event History
Aug 5, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2353?
CVE-2005-2353 is classified as a moderate severity vulnerability due to its local exploitability by users.
2
How do I fix CVE-2005-2353?
Fixing CVE-2005-2353 involves updating Thunderbird to a patched version to eliminate the symlink vulnerability.
3
Who is affected by CVE-2005-2353?
Users of Mozilla Thunderbird version 1.5.0.9 with debugging enabled are affected by CVE-2005-2353.
4
What is the nature of the attack in CVE-2005-2353?
The attack in CVE-2005-2353 involves a symlink attack allowing local users to create or overwrite arbitrary files.
5
Can CVE-2005-2353 be exploited remotely?
CVE-2005-2353 cannot be exploited remotely as it requires local user access to the system.