Seamonkey: Multiple vulnerabilities

Security Team  Contact Address

Updated October 16, 2006

1.  Gentoo Linux Security Advisory

Version Information

Advisory Reference GLSA 200610-04 / seamonkey
Release Date October 16, 2006
Latest Revision October 16, 2006: 01
Impact normal
Exploitable remote
Package Vulnerable versions Unaffected versions Architecture(s)
www-client/seamonkey < 1.0.5 >= 1.0.5 All supported architectures

Related bugreports: #147651

Synopsis

The Seamonkey project has reported multiple security vulnerabilities in the application.

2.  Impact Information

Background

The SeaMonkey project is a community effort to deliver production-quality releases of code derived from the application formerly known as 'Mozilla Application Suite'.

Description

A number of vulnerabilities have been found and fixed in Seamonkey. For details please consult the references below.

Impact

The most severe vulnerability involves enticing a user to visit a malicious website, crashing the application and executing arbitrary code with the rights of the user running Seamonkey.

3.  Resolution Information

Workaround

There is no known workaround at this time.

Resolution

All Seamonkey users should upgrade to the latest version:

Code Listing 3.1: Resolution

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/seamonkey-1.0.5"

4.  References