RHSA-2009:1432: Critical: seamonkey security update
SeaMonkey is an open source Web browser, email and newsgroup client, IRCchat client, and HTML editor.Several flaws were found in the processing of malformed web content. A webpage containing malicious content could cause SeaMonkey to crash or,potentially, execute arbitrary code with the privileges of the user runningSeaMonkey. (CVE-2009-3072, CVE-2009-3075)A use-after-free flaw was found in SeaMonkey. An attacker could use thisflaw to crash SeaMonkey or, potentially, execute arbitrary code with theprivileges of the user running SeaMonkey. (CVE-2009-3077)Dan Kaminsky discovered flaws in the way browsers such as SeaMonkey handleNULL characters in a certificate. If an attacker is able to get acarefully-crafted certificate signed by a Certificate Authority trusted bySeaMonkey, the attacker could use the certificate during aman-in-the-middle attack and potentially confuse SeaMonkey into acceptingit by mistake. (CVE-2009-2408)Descriptions in the dialogs when adding and removing PKCS #11 modules werenot informative. An attacker able to trick a user into installing amalicious PKCS #11 module could use this flaw to install their ownCertificate Authority certificates on a user's machine, making it possibleto trick the user into believing they are viewing a trusted site or,potentially, execute arbitrary code with the privileges of the user runningSeaMonkey. (CVE-2009-3076)A flaw was found in the way SeaMonkey displays the address bar whenwindow.open() is called in a certain way. An attacker could use this flawto conceal a malicious URL, possibly tricking a user into believing theyare viewing a trusted site. (CVE-2009-2654)Dan Kaminsky found that browsers still accept certificates with MD2 hashsignatures, even though MD2 is no longer considered a cryptographicallystrong algorithm. This could make it easier for an attacker to create amalicious certificate that would be treated as trusted by a browser. NSS(provided by SeaMonkey) now disables the use of MD2 and MD4 algorithmsinside signatures by default. (CVE-2009-2409)All SeaMonkey users should upgrade to these updated packages, which correctthese issues. After installing the update, SeaMonkey must be restarted forthe changes to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2009:1432?
The severity of RHSA-2009:1432 is classified as critical.
How do I fix RHSA-2009:1432?
To fix RHSA-2009:1432, update to the latest version of SeaMonkey that addresses the vulnerability.
What are the risks of exploiting RHSA-2009:1432?
Exploiting RHSA-2009:1432 could lead to crashes in SeaMonkey or potential arbitrary code execution.
Which versions of SeaMonkey are affected by RHSA-2009:1432?
RHSA-2009:1432 affects several versions of SeaMonkey that are prior to the patched release.
Is there any workaround for RHSA-2009:1432?
There are no documented workarounds for RHSA-2009:1432, and upgrading is the best option.