CVE-2005-3402

Publication date 1 November 2005

Last updated 17 July 2025


Ubuntu priority

Description

The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authentication information without detection via a man-in-the-middle (MITM) attack that bypasses TLS authentication or downgrades CRAM-MD5 authentication to plain authentication.

Status

Package Ubuntu Release Status
mozilla-thunderbird 7.04 feisty Ignored end of life
6.10 edgy Ignored end of life
6.06 LTS dapper Ignored end of life