NASLDB: SeaMonkey 2.x < 2.6.0 Multiple Vulnerabilities
General
ID: 57353
Name: SeaMonkey 2.x < 2.6.0 Multiple Vulnerabilities
Summary: Checks version of SeaMonkey
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C
CVSS Temporal Vector: –
Port: –
Family: Windows
Type: Local
Description
The installed version of SeaMonkey 2.x is earlier than 2.6.0. Such
versions are potentially affected by the following security issues :
– An out-of-bounds memory access error exists in the
‘SVG’ implementation and can be triggered when ‘SVG’
elements are removed during a ‘DOMAttrModified’ event
handler. (CVE-2011-3658)
– Various memory safety errors exist that can lead to
memory corruption and possible code execution.
(CVE-2011-3660)
– An error exists in the ‘YARR’ regular expression
library that can cause application crashes when
handling certain JavaScript statements. (CVE-2011-3661)
– It is possible to detect keystrokes using ‘SVG’
animation ‘accesskey’ events even when JavaScript is
disabled. (CVE-2011-3663)
– It is possible to crash the application when ‘OGG’
‘video’ elements are scaled to extreme sizes.
(CVE-2011-3665)
– A use-after-free error exists related to the function
‘nsHTMLSelectElement’ that can allow arbitrary code
execution during operations such as removal of a
parent node of an element. (CVE-2011-3671)
Exploiting
Exploit Available: True
Exploitability Ease: Exploits are available
Sources
CVE: CVE-2011-3658
OSVDB: –
Bugtraq: 51133
scipID: –
Timeline
Vulnerability Disclosure: 2011/12/20
Patch Release: 2011/12/20
Plugin Release: 2011/12/20
Plugin
Version: 1.11
Filename: seamonkey_26.nasl
Filesize: 4805 bytes
MD5 Hash: 3b149470bf3b170dc90030ecd6a73ccb
Identification: SMB/transport
Require Keys: SeaMonkey/Version
Dependencies: "mozilla_org_installed.nasl"
Copyright: This script is Copyright© 2011-2012 Tenable Network Security, Inc.
- Letzte Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













