Debian DSA-2227-1 : iceape - several vulnerabilities

critical Nessus Plugin ID 53602

Synopsis

The remote Debian host is missing a security-related update.

Description

Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of SeaMonkey :

- CVE-2011-0069 CVE-2011-0070 CVE-2011-0072 CVE-2011-0074 CVE-2011-0075 CVE-2011-0077 CVE-2011-0078 CVE-2011-0080 CVE-2011-0081 'Scoobidiver', Ian Beer Bob Clary, Henri Sivonen, Marco Bonardo, Mats Palmgren, Jesse Ruderman, Aki Kelin and Martin Barbella discovered memory corruption bugs, which may lead to the execution of arbitrary code.

- CVE-2011-0065 CVE-2011-0066 CVE-2011-0073 'regenrecht' discovered several dangling pointer vulnerabilities, which may lead to the execution of arbitrary code.

- CVE-2011-0067 Paul Stone discovered that Java applets could steal information from the autocompletion history.

- CVE-2011-0071 Soroush Dalili discovered a directory traversal vulnerability in handling resource URIs.

The oldstable distribution (lenny) is not affected. The iceape package only provides the XPCOM code.

Solution

Upgrade the iceape packages.

For the stable distribution (squeeze), this problem has been fixed in version 2.0.11-5.

See Also

https://security-tracker.debian.org/tracker/CVE-2011-0069

https://security-tracker.debian.org/tracker/CVE-2011-0070

https://security-tracker.debian.org/tracker/CVE-2011-0072

https://security-tracker.debian.org/tracker/CVE-2011-0074

https://security-tracker.debian.org/tracker/CVE-2011-0075

https://security-tracker.debian.org/tracker/CVE-2011-0077

https://security-tracker.debian.org/tracker/CVE-2011-0078

https://security-tracker.debian.org/tracker/CVE-2011-0080

https://security-tracker.debian.org/tracker/CVE-2011-0081

https://security-tracker.debian.org/tracker/CVE-2011-0065

https://security-tracker.debian.org/tracker/CVE-2011-0066

https://security-tracker.debian.org/tracker/CVE-2011-0073

https://security-tracker.debian.org/tracker/CVE-2011-0067

https://security-tracker.debian.org/tracker/CVE-2011-0071

https://packages.debian.org/source/squeeze/iceape

https://www.debian.org/security/2011/dsa-2227

Plugin Details

Severity: Critical

ID: 53602

File Name: debian_DSA-2227.nasl

Version: 1.20

Type: local

Agent: unix

Published: 5/2/2011

Updated: 1/4/2021

Supported Sensors: Agentless Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:iceape, cpe:/o:debian:debian_linux:6.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/30/2011

Exploitable With

CANVAS (White_Phosphorus)

Core Impact

Metasploit (Mozilla Firefox "nsTreeRange" Dangling Pointer Vulnerability)

Reference Information

CVE: CVE-2011-0065, CVE-2011-0066, CVE-2011-0067, CVE-2011-0069, CVE-2011-0070, CVE-2011-0071, CVE-2011-0072, CVE-2011-0073, CVE-2011-0074, CVE-2011-0075, CVE-2011-0077, CVE-2011-0078, CVE-2011-0080, CVE-2011-0081

DSA: 2227