Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 303763 (CVE-2009-4629) - mail-client/mozilla-thunderbird, www-client/seamonkey, www-client/mozilla-firefox DNS prefetching information disclosure (CVE-2009-{4629,4630})
Summary: mail-client/mozilla-thunderbird, www-client/seamonkey, www-client/mozilla-fir...
Status: RESOLVED WONTFIX
Alias: CVE-2009-4629
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.mozilla.org/show_bug...
Whiteboard: ~4 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-02-06 15:40 UTC by Stefan Behte (RETIRED)
Modified: 2010-02-06 15:46 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2010-02-06 15:40:18 UTC
CVE-2009-4629 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4629):
  Mozilla Necko, as used in Thunderbird 3.0.1, SeaMonkey, and other
  applications, performs DNS prefetching even when the app type is
  APP_TYPE_MAIL or APP_TYPE_EDITOR, which makes it easier for remote
  attackers to determine the network location of the application's user
  by logging DNS requests, as demonstrated by DNS requests triggered by
  reading text/plain e-mail messages in Thunderbird.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2010-02-06 15:41:12 UTC
CVE-2009-4630 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4630):
  Mozilla Necko, as used in Firefox, SeaMonkey, and other applications,
  performs DNS prefetching of domain names contained in links within
  local HTML documents, which makes it easier for remote attackers to
  determine the network location of the application's user by logging
  DNS requests.  NOTE: the vendor disputes the significance of this
  issue, stating "I don't think we necessarily need to worry about that
  case."

Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2010-02-06 15:46:07 UTC
Issues disputed by vendor.
Having looked into this, it seems to be privacy related, but not an absolutely security-related thing that can be patched.

This can be disabled in thunderbird manually (my guess is firefox, too).