Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 312647 - <www-client/seamonkey-2.0.3: issue tracking bug (CVE-2009-{1571,3388,3389,3979,3981,3982,3983,3984,3985,3986,3987,3988},CVE-2010-{0159,0160,0162,0167,0169,0171})
Summary: <www-client/seamonkey-2.0.3: issue tracking bug (CVE-2009-{1571,3388,3389,397...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B2 [noglsa]
Keywords:
Depends on: 314009 324735
Blocks:
  Show dependency tree
 
Reported: 2010-04-01 15:52 UTC by Alex Legler (RETIRED)
Modified: 2011-01-02 02:58 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 15:52:28 UTC
Seamonkey 2.0.3 issue tracking bug
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 15:53:10 UTC
CVE-2009-1571 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1571):
  Use-after-free vulnerability in the HTML parser in Mozilla Firefox
  3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2,
  and SeaMonkey before 2.0.3 allows remote attackers to execute
  arbitrary code via unspecified method calls that attempt to access
  freed objects in low-memory situations.

Comment 2 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 15:59:15 UTC
CVE-2009-3388 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3388):
  liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before
  2.0.1 might allow context-dependent attackers to cause a denial of
  service (application crash) or execute arbitrary code via unspecified
  vectors, related to "memory safety issues."

Comment 3 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 16:02:30 UTC
CVE-2009-3389 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3389):
  Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used
  in Mozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1,
  allows remote attackers to cause a denial of service (application
  crash) or possibly execute arbitrary code via a video with large
  dimensions.

Comment 4 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 16:04:58 UTC
CVE-2009-3979 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3979):
  Multiple unspecified vulnerabilities in the browser engine in Mozilla
  Firefox before 3.0.16 and 3.5.x before 3.5.6, SeaMonkey before 2.0.1,
  and Thunderbird allow remote attackers to cause a denial of service
  (memory corruption and application crash) or possibly execute
  arbitrary code via unknown vectors.

Comment 5 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 16:44:56 UTC
CVE-2009-3981 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3981):
  Unspecified vulnerability in the browser engine in Mozilla Firefox
  before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote
  attackers to cause a denial of service (memory corruption and
  application crash) or possibly execute arbitrary code via unknown
  vectors.

CVE-2009-3982 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3982):
  Multiple unspecified vulnerabilities in the JavaScript engine in
  Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and
  Thunderbird allow remote attackers to cause a denial of service
  (memory corruption and application crash) or possibly execute
  arbitrary code via unknown vectors.

Comment 6 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 16:45:49 UTC
CVE-2009-3983 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3983):
  Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey
  before 2.0.1, allows remote attackers to send authenticated requests
  to arbitrary applications by replaying the NTLM credentials of a
  browser user.

Comment 7 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 16:46:51 UTC
CVE-2009-3984 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3984):
  Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey
  before 2.0.1, allows remote attackers to spoof an SSL indicator for
  an http URL or a file URL by setting document.location to an https
  URL corresponding to a site that responds with a No Content (aka 204)
  status code and an empty body.

Comment 8 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 16:47:48 UTC
CVE-2009-3985 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3985):
  Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey
  before 2.0.1, allows remote attackers to associate spoofed content
  with an invalid URL by setting document.location to this URL, and
  then writing arbitrary web script or HTML to the associated blank
  document, a related issue to CVE-2009-2654.

Comment 9 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 16:48:33 UTC
CVE-2009-3986 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3986):
  Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey
  before 2.0.1, allows remote attackers to execute arbitrary JavaScript
  with chrome privileges by leveraging a reference to a chrome window
  from a content window, related to the window.opener property.

Comment 10 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 16:49:14 UTC
CVE-2009-3987 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3987):
  The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and
  3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different
  exception messages depending on whether the referenced COM object is
  listed in the registry, which allows remote attackers to obtain
  potentially sensitive information about installed software by making
  multiple calls that specify the ProgID values of different COM
  objects.

Comment 11 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 16:49:58 UTC
CVE-2009-3988 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3988):
  Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and
  SeaMonkey before 2.0.3, does not properly restrict read access to
  object properties in showModalDialog, which allows remote attackers
  to bypass the Same Origin Policy and conduct cross-site scripting
  (XSS) attacks via crafted dialogArguments values.

Comment 12 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 16:51:31 UTC
CVE-2010-0159 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0159):
  The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x
  before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3
  allows remote attackers to cause a denial of service (memory
  corruption and application crash) or possibly execute arbitrary code
  via vectors related to the nsBlockFrame::StealFrame function in
  layout/generic/nsBlockFrame.cpp, and unspecified other vectors.

Comment 13 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 16:52:14 UTC
CVE-2010-0160 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0160):
  The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18
  and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly
  handle array data types for posted messages, which allows remote
  attackers to cause a denial of service (heap memory corruption and
  application crash) or possibly execute arbitrary code via unspecified
  vectors.

Comment 14 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 16:53:15 UTC
CVE-2010-0162 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0162):
  Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and
  SeaMonkey before 2.0.3, does not properly support the
  application/octet-stream content type as a protection mechanism
  against execution of web script in certain circumstances involving
  SVG and the EMBED element, which allows remote attackers to bypass
  the Same Origin Policy and conduct cross-site scripting (XSS) attacks
  via an embedded SVG document.

Comment 15 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 16:59:55 UTC
CVE-2010-0167 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0167):
  The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x
  before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and
  SeaMonkey before 2.0.3 allows remote attackers to cause a denial of
  service (memory corruption and application crash) and possibly
  execute arbitrary code via vectors related to (1)
  layout/generic/nsBlockFrame.cpp and (2) the _evaluate function in
  modules/plugin/base/src/nsNPAPIPlugin.cpp.

Comment 16 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-01 17:05:45 UTC
CVE-2010-0169 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0169):
  The CSSLoaderImpl::DoSheetComplete function in
  layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18,
  3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2;
  and SeaMonkey before 2.0.3 changes the case of certain strings in a
  stylesheet before adding this stylesheet to the XUL cache, which
  might allow remote attackers to modify the browser's font and other
  CSS attributes, and potentially disrupt rendering of a web page, by
  forcing the browser to perform this erroneous stylesheet caching.

CVE-2010-0171 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0171):
  Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x
  before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3
  allow remote attackers to perform cross-origin keystroke capture, and
  possibly conduct cross-site scripting (XSS) attacks, by using the
  addEventListener and setTimeout functions in conjunction with a
  wrapped object.  NOTE: this vulnerability exists because of an
  incomplete fix for CVE-2007-3736.

Comment 17 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2010-04-01 17:21:02 UTC
I've already added seamonkey-2.0.4 to the mozilla-overlay. But since seamonkey-2 is still p.masked I think this is no topic for security herd...
Comment 18 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2010-04-03 02:37:17 UTC
seamonkey-2.0.4 is now in the tree and all older 2.0.x versions were removed. 
Comment 19 Tim Sammut (RETIRED) gentoo-dev 2011-01-02 02:58:13 UTC
Closing noglsa as vulnerable packages are no longer in the tree, <www-client/seamonkey-2.0.3 was never stable, and <www-client/seamonkey-bin-2.0.3 did not exist.