CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
Percentile
95.9%
CentOS Errata and Security Advisory CESA-2009:0437-02
SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-1303, CVE-2009-1305)
Several flaws were found in the way malformed web content was processed. A
web page containing malicious content could execute arbitrary JavaScript in
the context of the site, possibly presenting misleading data to a user, or
stealing sensitive information such as login credentials. (CVE-2009-0652,
CVE-2009-1306, CVE-2009-1307, CVE-2009-1309, CVE-2009-1312)
A flaw was found in the way SeaMonkey saved certain web pages to a local
file. If a user saved the inner frame of a web page containing POST data,
the POST data could be revealed to the inner frame, possibly surrendering
sensitive information such as login credentials. (CVE-2009-1311)
All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.
Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2009-April/077992.html
Affected packages:
seamonkey
seamonkey-chat
seamonkey-devel
seamonkey-dom-inspector
seamonkey-js-debugger
seamonkey-mail
seamonkey-nspr
seamonkey-nspr-devel
seamonkey-nss
seamonkey-nss-devel
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
CentOS | 2 | i386 | seamonkey | < 1.0.9-0.33.el2.c2.1 | seamonkey-1.0.9-0.33.el2.c2.1.i386.rpm |
CentOS | 2 | i386 | seamonkey-chat | < 1.0.9-0.33.el2.c2.1 | seamonkey-chat-1.0.9-0.33.el2.c2.1.i386.rpm |
CentOS | 2 | i386 | seamonkey-devel | < 1.0.9-0.33.el2.c2.1 | seamonkey-devel-1.0.9-0.33.el2.c2.1.i386.rpm |
CentOS | 2 | i386 | seamonkey-dom-inspector | < 1.0.9-0.33.el2.c2.1 | seamonkey-dom-inspector-1.0.9-0.33.el2.c2.1.i386.rpm |
CentOS | 2 | i386 | seamonkey-js-debugger | < 1.0.9-0.33.el2.c2.1 | seamonkey-js-debugger-1.0.9-0.33.el2.c2.1.i386.rpm |
CentOS | 2 | i386 | seamonkey-mail | < 1.0.9-0.33.el2.c2.1 | seamonkey-mail-1.0.9-0.33.el2.c2.1.i386.rpm |
CentOS | 2 | i386 | seamonkey-nspr | < 1.0.9-0.33.el2.c2.1 | seamonkey-nspr-1.0.9-0.33.el2.c2.1.i386.rpm |
CentOS | 2 | i386 | seamonkey-nspr-devel | < 1.0.9-0.33.el2.c2.1 | seamonkey-nspr-devel-1.0.9-0.33.el2.c2.1.i386.rpm |
CentOS | 2 | i386 | seamonkey-nss | < 1.0.9-0.33.el2.c2.1 | seamonkey-nss-1.0.9-0.33.el2.c2.1.i386.rpm |
CentOS | 2 | i386 | seamonkey-nss-devel | < 1.0.9-0.33.el2.c2.1 | seamonkey-nss-devel-1.0.9-0.33.el2.c2.1.i386.rpm |