openSUSE 10 Security Update : seamonkey (seamonkey-5657)
Critical Nessus Plugin ID 34360
SynopsisThe remote openSUSE host is missing a security update.
DescriptionThis patch updates SeaMonkey to version 1.1.12, fixing security and other bugs :
MFSA 2008-45 / CVE-2008-4069: XBM image uninitialized memory reading
MFSA 2008-44 / CVE-2008-4067 / CVE-2008-4068: resource: traversal vulnerabilities
CVE-2008-4064: David Maciejak and Drew Yao reported crashes in graphics rendering which only affected Firefox 3.
MFSA 2008-41 Privilege escalation via XPCnativeWrapper pollution CVE-2008-4058: XPCnativeWrapper pollution bugs CVE-2008-4059:
XPCnativeWrapper pollution (Firefox 2) CVE-2008-4060: Documents without script handling objects
MFSA 2008-40 / CVE-2008-3837: Forced mouse drag
MFSA 2008-38 / CVE-2008-3835: nsXMLDocument::OnChannelRedirect() same-origin violation
MFSA 2008-37 / CVE-2008-0016: UTF-8 URL stack buffer overflow
Details can be found here:
SolutionUpdate the affected seamonkey packages.