Mozilla Thunderbird < 2.0.0.23 Certificate Authority (CA) Common Null Byte Handling SSL MiTM Weakness
medium Log Correlation Engine Plugin ID 801349
Synopsis
The remote host contains a mail client that is affected by a security bypass vulnerability.
Description
The installed version of Mozilla Thunderbird is earlier than 2.0.0.23. Such versions are potentially affected by the following security issue : - The client can be fooled into trusting a malicious SSL server certificate with a null character in the host name. (MFSA 2009-42)