RHSA-2009:1432: Critical: seamonkey security update

Published Sep 9, 2009
·
Updated

SeaMonkey is an open source Web browser, email and newsgroup client, IRCchat client, and HTML editor.Several flaws were found in the processing of malformed web content. A webpage containing malicious content could cause SeaMonkey to crash or,potentially, execute arbitrary code with the privileges of the user runningSeaMonkey. (CVE-2009-3072, CVE-2009-3075)A use-after-free flaw was found in SeaMonkey. An attacker could use thisflaw to crash SeaMonkey or, potentially, execute arbitrary code with theprivileges of the user running SeaMonkey. (CVE-2009-3077)Dan Kaminsky discovered flaws in the way browsers such as SeaMonkey handleNULL characters in a certificate. If an attacker is able to get acarefully-crafted certificate signed by a Certificate Authority trusted bySeaMonkey, the attacker could use the certificate during aman-in-the-middle attack and potentially confuse SeaMonkey into acceptingit by mistake. (CVE-2009-2408)Descriptions in the dialogs when adding and removing PKCS #11 modules werenot informative. An attacker able to trick a user into installing amalicious PKCS #11 module could use this flaw to install their ownCertificate Authority certificates on a user's machine, making it possibleto trick the user into believing they are viewing a trusted site or,potentially, execute arbitrary code with the privileges of the user runningSeaMonkey. (CVE-2009-3076)A flaw was found in the way SeaMonkey displays the address bar whenwindow.open() is called in a certain way. An attacker could use this flawto conceal a malicious URL, possibly tricking a user into believing theyare viewing a trusted site. (CVE-2009-2654)Dan Kaminsky found that browsers still accept certificates with MD2 hashsignatures, even though MD2 is no longer considered a cryptographicallystrong algorithm. This could make it easier for an attacker to create amalicious certificate that would be treated as trusted by a browser. NSS(provided by SeaMonkey) now disables the use of MD2 and MD4 algorithmsinside signatures by default. (CVE-2009-2409)All SeaMonkey users should upgrade to these updated packages, which correctthese issues. After installing the update, SeaMonkey must be restarted forthe changes to take effect.

Affected Software

1 affected component
Mozilla SeaMonkey

Remediation

Event History

Sep 9, 2009
Advisory Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2009:1432?

The severity of RHSA-2009:1432 is classified as critical.

2

How do I fix RHSA-2009:1432?

To fix RHSA-2009:1432, update to the latest version of SeaMonkey that addresses the vulnerability.

3

What are the risks of exploiting RHSA-2009:1432?

Exploiting RHSA-2009:1432 could lead to crashes in SeaMonkey or potential arbitrary code execution.

4

Which versions of SeaMonkey are affected by RHSA-2009:1432?

RHSA-2009:1432 affects several versions of SeaMonkey that are prior to the patched release.

5

Is there any workaround for RHSA-2009:1432?

There are no documented workarounds for RHSA-2009:1432, and upgrading is the best option.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203