[SECURITY] Fedora 8 Update: seamonkey-1.1.12-1.fc8

updates at fedoraproject.org updates at fedoraproject.org
Sun Sep 28 18:41:42 UTC 2008


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-8401
2008-09-27 03:03:26
--------------------------------------------------------------------------------

Name        : seamonkey
Product     : Fedora 8
Version     : 1.1.12
Release     : 1.fc8
URL         : http://www.mozilla.org/projects/seamonkey/
Summary     : Web browser, e-mail, news, IRC client, HTML editor
Description :
SeaMonkey is an all-in-one Internet application suite. It includes
a browser, mail/news client, IRC client, JavaScript debugger, and
a tool to inspect the DOM for web pages. It is derived from the
application formerly known as Mozilla Application Suite.

--------------------------------------------------------------------------------
Update Information:

Updated seamonkey packages that fix several security issues are now available
for Fedora 8 and Fedora 9.    This update has been rated as having critical
security impact by the Red Hat Security Response Team.    SeaMonkey is an open
source Web browser, advanced email and newsgroup client, IRC chat client, and
HTML editor.    Several flaws were found in the processing of malformed web
content. A web page containing malicious content could cause SeaMonkey to crash
or, potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2008-0016, CVE-2008-4058, CVE-2008-4059, CVE-2008-4060, CVE-2008-4061,
CVE-2008-4062)    Several flaws were found in the way malformed web content was
displayed. A web page containing specially crafted content could potentially
trick a SeaMonkey user into surrendering sensitive information. (CVE-2008-3835,
CVE-2008-4067, CVE-2008-4068, CVE-2008-4069)    A flaw was found in the way
SeaMonkey handles mouse click events. A web page containing specially crafted
JavaScript code could move the content window while a mouse-button was pressed,
causing any item under the pointer to be dragged. This could, potentially, cause
the user to perform an unsafe drag-and-drop action. (CVE-2008-3837)    A flaw
was found in SeaMonkey that caused certain characters to be stripped from
JavaScript code. This flaw could allow malicious JavaScript to bypass or evade
script filters. (CVE-2008-4065, CVE-2008-4066)    All SeaMonkey users should
upgrade to these updated packages, which contain patches to resolve these
issues.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Sep 25 2008 Christopher Aillon <caillon at redhat.com> - 1.1.12-1
- Update to 1.1.12
* Tue Jul 15 2008 Christopher Aillon <caillon at redhat.com> - 1.1.11-1
- Update to 1.1.11
* Tue Jul  8 2008 Christopher Aillon <caillon at redhat.com> - 1.1.10-1
- Update to 1.1.10
- Use bullet characters to match GTK+
* Thu Apr 17 2008 Kai Engert <kengert at redhat.com> - 1.1.9-2
- add several upstream patches, not yet released:
  425576 (crash), 323508, 378132, 390295, 421622
* Fri Mar 28 2008 Kai Engert <kengert at redhat.com> - 1.1.9-1
- SeaMonkey 1.1.9
* Fri Feb  8 2008 Kai Engert <kengert at redhat.com> - 1.1.8-1
- SeaMonkey 1.1.8
* Sun Dec  2 2007 Kai Engert <kengert at redhat.com> - 1.1.7-1
- SeaMonkey 1.1.7
* Mon Nov  5 2007 Kai Engert <kengert at redhat.com> - 1.1.6-1
- SeaMonkey 1.1.6
* Fri Oct 19 2007 Kai Engert <kengert at redhat.com> - 1.1.5-2
- SeaMonkey 1.1.5
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update seamonkey' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------




More information about the package-announce mailing list