Oval Definition:oval:com.redhat.rhsa:def:20090437
Revision Date:2009-04-21Version:636
Title:RHSA-2009:0437: seamonkey security update (Critical)
Description:SeaMonkey is an open source Web browser, email and newsgroup client, IRC chat client, and HTML editor.

  • Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause SeaMonkey to crash or, potentially, execute arbitrary code as the user running SeaMonkey. (CVE-2009-1303, CVE-2009-1305)

  • Several flaws were found in the way malformed web content was processed. A web page containing malicious content could execute arbitrary JavaScript in the context of the site, possibly presenting misleading data to a user, or stealing sensitive information such as login credentials. (CVE-2009-0652, CVE-2009-1306, CVE-2009-1307, CVE-2009-1309, CVE-2009-1312)

  • A flaw was found in the way SeaMonkey saved certain web pages to a local file. If a user saved the inner frame of a web page containing POST data, the POST data could be revealed to the inner frame, possibly surrendering sensitive information such as login credentials. (CVE-2009-1311)

    All SeaMonkey users should upgrade to these updated packages, which correct these issues. After installing the update, SeaMonkey must be restarted for the changes to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-0652
    CVE-2009-1303
    CVE-2009-1305
    CVE-2009-1306
    CVE-2009-1307
    CVE-2009-1309
    CVE-2009-1311
    CVE-2009-1312
    RHSA-2009:0437
    RHSA-2009:0437-02
    RHSA-2009:0437-02
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • seamonkey-nss-devel is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-nss-devel is signed with Red Hat master key
  • seamonkey-nspr-devel is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-nspr-devel is signed with Red Hat master key
  • seamonkey is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey is signed with Red Hat master key
  • seamonkey-mail is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-mail is signed with Red Hat master key
  • seamonkey-nss is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-nss is signed with Red Hat master key
  • seamonkey-js-debugger is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-js-debugger is signed with Red Hat master key
  • seamonkey-dom-inspector is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-dom-inspector is signed with Red Hat master key
  • seamonkey-chat is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-chat is signed with Red Hat master key
  • seamonkey-nspr is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-nspr is signed with Red Hat master key
  • seamonkey-devel is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • seamonkey-chat is earlier than 0:1.0.9-41.el4
  • AND seamonkey-chat is signed with Red Hat master key
  • seamonkey-devel is earlier than 0:1.0.9-41.el4
  • AND seamonkey-devel is signed with Red Hat master key
  • seamonkey-dom-inspector is earlier than 0:1.0.9-41.el4
  • AND seamonkey-dom-inspector is signed with Red Hat master key
  • seamonkey-js-debugger is earlier than 0:1.0.9-41.el4
  • AND seamonkey-js-debugger is signed with Red Hat master key
  • seamonkey is earlier than 0:1.0.9-41.el4
  • AND seamonkey is signed with Red Hat master key
  • seamonkey-mail is earlier than 0:1.0.9-41.el4
  • AND seamonkey-mail is signed with Red Hat master key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • seamonkey is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey is signed with Red Hat master key
  • seamonkey-chat is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-chat is signed with Red Hat master key
  • seamonkey-devel is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-devel is signed with Red Hat master key
  • seamonkey-dom-inspector is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-dom-inspector is signed with Red Hat master key
  • seamonkey-js-debugger is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-js-debugger is signed with Red Hat master key
  • seamonkey-mail is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-mail is signed with Red Hat master key
  • seamonkey-nspr is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-nspr is signed with Red Hat master key
  • seamonkey-nspr-devel is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-nspr-devel is signed with Red Hat master key
  • seamonkey-nss is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-nss is signed with Red Hat master key
  • seamonkey-nss-devel is earlier than 0:1.0.9-0.37.el3
  • AND seamonkey-nss-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • seamonkey is earlier than 0:1.0.9-41.el4
  • AND seamonkey is signed with Red Hat master key
  • seamonkey-chat is earlier than 0:1.0.9-41.el4
  • AND seamonkey-chat is signed with Red Hat master key
  • seamonkey-devel is earlier than 0:1.0.9-41.el4
  • AND seamonkey-devel is signed with Red Hat master key
  • seamonkey-dom-inspector is earlier than 0:1.0.9-41.el4
  • AND seamonkey-dom-inspector is signed with Red Hat master key
  • seamonkey-js-debugger is earlier than 0:1.0.9-41.el4
  • AND seamonkey-js-debugger is signed with Red Hat master key
  • seamonkey-mail is earlier than 0:1.0.9-41.el4
  • AND seamonkey-mail is signed with Red Hat master key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • seamonkey is earlier than 0:1.0.9-41.el4
  • AND seamonkey is signed with Red Hat redhatrelease2 key
  • seamonkey-chat is earlier than 0:1.0.9-41.el4
  • AND seamonkey-chat is signed with Red Hat redhatrelease2 key
  • seamonkey-devel is earlier than 0:1.0.9-41.el4
  • AND seamonkey-devel is signed with Red Hat redhatrelease2 key
  • seamonkey-dom-inspector is earlier than 0:1.0.9-41.el4
  • AND seamonkey-dom-inspector is signed with Red Hat redhatrelease2 key
  • seamonkey-js-debugger is earlier than 0:1.0.9-41.el4
  • AND seamonkey-js-debugger is signed with Red Hat redhatrelease2 key
  • seamonkey-mail is earlier than 0:1.0.9-41.el4
  • AND seamonkey-mail is signed with Red Hat redhatrelease2 key
  • BACK