[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2010:0546 -- centos 3 x86_64 seamonkey

ID: oval:org.secpod.oval:def:200004Date: (C)2012-01-31   (M)2024-02-19
Class: PATCHFamily: unix




SeaMonkey is an open source web browser, email and newsgroup client, IRC chat client, and HTML editor. Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause SeaMonkey to crash or, potentially, execute arbitrary code with the privileges of the user running SeaMonkey. A memory corruption flaw was found in the way SeaMonkey decoded certain PNG images. An attacker could create a specially-crafted PNG image that, when opened, could cause SeaMonkey to crash or, potentially, execute arbitrary code with the privileges of the user running SeaMonkey. A same-origin policy bypass flaw was found in SeaMonkey. An attacker could create a malicious web page that, when viewed by a victim, could steal private data from a different website the victim has loaded with SeaMonkey. A flaw was found in the way SeaMonkey displayed the location bar when visiting a secure web page. A malicious server could use this flaw to present data that appears to originate from a secure server, even though it does not. All SeaMonkey users should upgrade to these updated packages, which correct these issues. After installing the update, SeaMonkey must be restarted for the changes to take effect.

Platform:
CentOS 3
Product:
seamonkey
Reference:
CESA-2010:0546
CVE-2010-1205
CVE-2010-1211
CVE-2010-1214
CVE-2010-2751
CVE-2010-2753
CVE-2010-2754
CVE    6
CVE-2010-1211
CVE-2010-2751
CVE-2010-1205
CVE-2010-2754
...
CPE    1
cpe:/o:centos:centos:3

© SecPod Technologies