SeaMonkey < 2.0 Multiple Vulnerabilities

High Nessus Plugin ID 42307


A web browser on the remote host is affected by multiple vulnerabilities.


The installed version of SeaMonkey is earlier than 2.0. Such versions are potentially affected by the following security issues :

- Provided the browser is configured to use Proxy Auto-configuration it may be possible for an attacker to crash the browser or execute arbitrary code.
(MFSA 2009-55)

- Mozilla's GIF image parser is affected by a heap-based buffer overflow. (MFSA 2009-56)

- If a file contains right-to-left override character (RTL) in the filename it may be possible for an attacker to obfuscate the filename and extension of the file being downloaded. (MFSA 2009-62)


Upgrade to SeaMonkey 2.0 or later.

See Also

Plugin Details

Severity: High

ID: 42307

File Name: seamonkey_20.nasl

Version: $Revision: 1.13 $

Type: local

Agent: windows

Family: Windows

Published: 2009/10/29

Modified: 2017/06/12

Dependencies: 20862

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:mozilla:seamonkey

Required KB Items: SeaMonkey/Version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2009/10/27

Vulnerability Publication Date: 2009/10/27

Reference Information

CVE: CVE-2009-3372, CVE-2009-3373, CVE-2009-3376

BID: 36855, 36856, 36867

OSVDB: 59389, 59393, 59394

CWE: 16, 119