RHSA-2010:0546: Critical: seamonkey security update
SeaMonkey is an open source web browser, email and newsgroup client, IRCchat client, and HTML editor.Several flaws were found in the processing of malformed web content. A webpage containing malicious content could cause SeaMonkey to crash or,potentially, execute arbitrary code with the privileges of the user runningSeaMonkey. (CVE-2010-1211, CVE-2010-2753, CVE-2010-1214)A memory corruption flaw was found in the way SeaMonkey decoded certain PNGimages. An attacker could create a specially-crafted PNG image that, whenopened, could cause SeaMonkey to crash or, potentially, execute arbitrarycode with the privileges of the user running SeaMonkey. (CVE-2010-1205)A same-origin policy bypass flaw was found in SeaMonkey. An attacker couldcreate a malicious web page that, when viewed by a victim, could stealprivate data from a different website the victim has loaded with SeaMonkey.(CVE-2010-2754)A flaw was found in the way SeaMonkey displayed the location bar whenvisiting a secure web page. A malicious server could use this flaw topresent data that appears to originate from a secure server, even though itdoes not. (CVE-2010-2751)All SeaMonkey users should upgrade to these updated packages, which correctthese issues. After installing the update, SeaMonkey must be restarted forthe changes to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0546?
The severity of RHSA-2010:0546 is categorized as moderate due to the potential for SeaMonkey to crash or execute arbitrary code when processing malformed web content.
How do I fix RHSA-2010:0546?
To fix RHSA-2010:0546, upgrade to the patched version 1.0.9-60.el4 of the affected SeaMonkey packages.
Which software versions are affected by RHSA-2010:0546?
RHSA-2010:0546 affects SeaMonkey versions up to and including 1.0.9-60.el4.
What types of attacks does RHSA-2010:0546 protect against?
RHSA-2010:0546 protects against attacks that exploit vulnerabilities in SeaMonkey to crash the application or potentially execute arbitrary code.
What are the components affected by RHSA-2010:0546?
RHSA-2010:0546 affects several components of SeaMonkey including the main browser, email client, and development tools.