[Full-Disclosure] Mozilla Thunderbird 0.8 / Firefox 0.9.3 temporary files (local)

From: Martin (broadcast_at_ptraced.net)
Date: 10/24/04

  • Next message: Habonator _: "[Full-Disclosure] XSS vulnerabilities in several german communities + aol search"
    To: full-disclosure@lists.netsys.com
    Date: Sun, 24 Oct 2004 19:09:05 -0200
    
    
    

    Advisory attached.

    
    

    Mozilla Thunderbird 0.8 / Firefox 0.9.3 temporary files (local)

    Martin (broadcast@ptraced.net)

    -------------------
    Program Description
    -------------------

    "Thunderbird, our latest email program, includes intelligent spam
    filters, spell-checking, security, customization, and newsgroups
    support."

    www.mozilla.org

    -------------------
    Problem Description
    -------------------

    When opening an attachment, or a link included in an email, Thunderbird
    prompts the user with a dialog box, giving the choice to "Save to Disk"
    or to "Open with" <default program>.

    For example, we receive a PDF document attached, and on the Attachments
    section, we choose "Open".

    broadcast:/tmp$ ls -l *.pdf
    -rw------- 1 broadcast broadcast 2002560 2004-10-24 18:38 wskbq43m.pdf

    While the dialog box is still open, the file permissions are OK, and the
    filename is random (except for the extension).
    If we choose to save it to disk, and check /tmp again:

    broadcast:/tmp$ ls -l *.pdf
    ls: *.pdf: No such file or directory

    Great, it's gone. Now let's choose to open it with the default viewer
    (in my case, xpdf).
    Again, while the dialog box is open, there are no apparent problems.

    broadcast:/tmp$ ls -l *.pdf
    -rw------- 1 broadcast broadcast 2002560 2004-10-24 18:42 hp1h30si.pd

    But after choosing to open it with xpdf:

    broadcast:/tmp$ ls -l *.pdf
    -rw-r--r-- 1 broadcast broadcast 2002560 2004-10-24 18:42 programming.pdf

    The file becomes world readable, until the user closes xpdf, or whatever
    application he chose to read the attachment.
    Also, the filename becomes predictable, but if the filename already
    exists on /tmp, Thunderbird will choose a similar filename, and won't
    work on the existing one.

    This exact issue affects Mozilla Firefox 0.9.3. I haven't tested
    older/newer versions, and all of this was tested under Debian Unstable.

    A copy of this advisory and future updates on this issue may be found on:
    http://broadcast.ptraced.net/advisories/008-firefox.thunderbird.txt

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Habonator _: "[Full-Disclosure] XSS vulnerabilities in several german communities + aol search"

    Relevant Pages

    • Re: Send to mail recipient greyed out (Office for Mac)
      ... It works fine here when my default email program is Entourage or Mail, but when I set the default email program to Thunderbird, File | Send To as Attachment greys out for me too. ... I believe, but am not entirely sure, that in general stuff that was in the registry in Windows is in preferences on the Mac. ...
      (microsoft.public.mac.office.word)
    • Re: send in mail menu item in nautilus
      ... filename" in to field. ... I neither use thunderbird for mail, ... general advice. ... (Currently running FC4, in case that's important to the thread) ...
      (Fedora)
    • Re: OT: Alternatives to Outlook Express?
      ... I've been using it for a email program ... Like Mozilla Firefox, its ... I agree with you about the memory issues - both Firefox and Thunderbird ...
      (alt.sports.baseball.ny-yankees)
    • Re: OT: Eudora a good alternative to Thunderbird?
      ... Eudora now says on the site that the no-nagware version ... will still be around as an alternative (I like Thunderbird ... POP3 - which may make a difference. ... IMHO an email program shall ...
      (sci.electronics.design)
    • Re: [opensuse] Its Bug? Thunderbird doesnt open "file name.eml" (from konqueror, konsole ...)
      ... On Tuesday 16 June 2009 13:13:01 Alexander R wrote: ... Thunderbird, then a TB not open this file. ... If filename has no space, ... Andreas Jaeger, Director Platform / openSUSE, aj@xxxxxxx ...
      (SuSE)

  • Quantcast