NASLDB: SuSE Security Update: seamonkey: Security update to version 1.1.1. (seamonkey-2691)
General
ID: 27439
Name: SuSE Security Update: seamonkey: Security update to version 1.1.1. (seamonkey-2691)
Summary: Check for the seamonkey-2691 package
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C
CVSS Temporal Vector: –
Port: 0
Family: SuSE Local Security Checks
Type: –
Description
This security update brings Mozilla Seamonkey to version
1.1.1.
http://www.mozilla.org/projects/security/known-vulnerabilities.html for more details.
It includes fixes to the following security problems:
– MFSA 2007-01: As part of the Firefox 2.0.0.2 and
1.5.0.10 update releases several bugs were fixed to
improve the stability of the browser. Some of these were
crashes that showed evidence of memory corruption and we
presume that with enough effort at least some of these
could be exploited to run arbitrary code. These fixes
affected the layout engine (CVE-2007-0775), SVG renderer
(CVE-2007-0776) and javascript engine (CVE-2007-0777).
– MFSA 2007-02: Various enhancements were done to make XSS
exploits against websites less effective. These included
fixes for invalid trailing characters (CVE-2007-0995),
child frame character set inheritance (CVE-2007-0996),
password form injection (CVE-2006-6077), and the Adobe
Reader universal XSS problem.
– MFSA 2007-03/CVE-2007-0778: AAd reported a potential disk
cache collision that could be exploited by remote
attackers to steal confidential data or execute code.
– MFSA 2007-04/CVE-2007-0779: David Eckel reported that
browser UI elements—such as the host name and security
indicators—could be spoofed by using a large, mostly
transparent, custom cursor and adjusting the CSS3 hotspot
property so that the visible part of the cursor floated
outside the browser content area.
– MFSA 2007-05: Manually opening blocked popups could be
exploited by remote attackers to allow XSS attacks
(CVE-2007-0780) or to execute code in local files
(CVE-2007-0800).
– MFSA 2007-06: Two buffer overflows were found in the NSS
handling of Mozilla.
CVE-2007-0008: SSL clients such as Firefox and
Thunderbird can suffer a buffer overflow if a malicious
server presents a certificate with a public key that is too
small to encrypt the entire ‘Master Secret’. Exploiting
this overflow appears to be unreliable but possible if the
SSLv2 protocol is enabled.
CVE-2007-0009: Servers that use NSS for the SSLv2
protocol can be exploited by a client that presents a
‘Client Master Key’ with invalid length values in any of
several fields that are used without adequate error
checking. This can lead to a buffer overflow that
presumably could be exploitable.
– MFSA 2007-06/CVE-2007-0981: Michal Zalewski demonstrated
that setting location.hostname to a value with embedded
null characters can confuse the browsers domain checks.
Setting the value triggers a load, but the networking
software reads the hostname only up to the null character
while other checks for ‘parent domain’ start at the right
and so can have a completely different idea of what the
current host is.
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2007-0775
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: –
Plugin Release: 2007/10/17
Plugin
Version: 1.9
Filename: suse_seamonkey-2691.nasl
Filesize: 5043 bytes
MD5 Hash: e66c2c5f09da7d02f5cf1db99e79d968
Identification: Host/SuSE/rpm-list
Require Keys: Host/SuSE/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2007-2010 Tenable Network Security, Inc.
- Letzte Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













