Oval Definition:oval:com.redhat.rhsa:def:20091673
Revision Date:2009-12-16Version:640
Title:RHSA-2009:1673: seamonkey security update (Critical)
Description:SeaMonkey is an open source Web browser, email and newsgroup client, IRC chat client, and HTML editor.

  • Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause SeaMonkey to crash or, potentially, execute arbitrary code with the privileges of the user running SeaMonkey. (CVE-2009-3979)

  • A flaw was found in the SeaMonkey NT Lan Manager (NTLM) authentication protocol implementation. If an attacker could trick a local user that has NTLM credentials into visiting a specially-crafted web page, they could send arbitrary requests, authenticated with the user's NTLM credentials, to other applications on the user's system. (CVE-2009-3983)

  • A flaw was found in the way SeaMonkey displayed the SSL location bar indicator. An attacker could create an unencrypted web page that appears to be encrypted, possibly tricking the user into believing they are visiting a secure page. (CVE-2009-3984)

    All SeaMonkey users should upgrade to these updated packages, which correct these issues. After installing the update, SeaMonkey must be restarted for the changes to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-3979
    CVE-2009-3983
    CVE-2009-3984
    RHSA-2009:1673
    RHSA-2009:1673-01
    RHSA-2009:1673-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • seamonkey-dom-inspector is earlier than 0:1.0.9-0.48.el3
  • AND seamonkey-dom-inspector is signed with Red Hat master key
  • seamonkey-nspr-devel is earlier than 0:1.0.9-0.48.el3
  • AND seamonkey-nspr-devel is signed with Red Hat master key
  • seamonkey-devel is earlier than 0:1.0.9-0.48.el3
  • AND seamonkey-devel is signed with Red Hat master key
  • seamonkey is earlier than 0:1.0.9-0.48.el3
  • AND seamonkey is signed with Red Hat master key
  • seamonkey-nss-devel is earlier than 0:1.0.9-0.48.el3
  • AND seamonkey-nss-devel is signed with Red Hat master key
  • seamonkey-js-debugger is earlier than 0:1.0.9-0.48.el3
  • AND seamonkey-js-debugger is signed with Red Hat master key
  • seamonkey-nspr is earlier than 0:1.0.9-0.48.el3
  • AND seamonkey-nspr is signed with Red Hat master key
  • seamonkey-mail is earlier than 0:1.0.9-0.48.el3
  • AND seamonkey-mail is signed with Red Hat master key
  • seamonkey-chat is earlier than 0:1.0.9-0.48.el3
  • AND seamonkey-chat is signed with Red Hat master key
  • seamonkey-nss is earlier than 0:1.0.9-0.48.el3
  • AND seamonkey-nss is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • seamonkey-devel is earlier than 0:1.0.9-51.el4_8
  • AND seamonkey-devel is signed with Red Hat master key
  • seamonkey-dom-inspector is earlier than 0:1.0.9-51.el4_8
  • AND seamonkey-dom-inspector is signed with Red Hat master key
  • seamonkey is earlier than 0:1.0.9-51.el4_8
  • AND seamonkey is signed with Red Hat master key
  • seamonkey-chat is earlier than 0:1.0.9-51.el4_8
  • AND seamonkey-chat is signed with Red Hat master key
  • seamonkey-mail is earlier than 0:1.0.9-51.el4_8
  • AND seamonkey-mail is signed with Red Hat master key
  • seamonkey-js-debugger is earlier than 0:1.0.9-51.el4_8
  • AND seamonkey-js-debugger is signed with Red Hat master key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • seamonkey is earlier than 0:1.0.9-51.el4_8
  • AND seamonkey is signed with Red Hat redhatrelease2 key
  • seamonkey-chat is earlier than 0:1.0.9-51.el4_8
  • AND seamonkey-chat is signed with Red Hat redhatrelease2 key
  • seamonkey-devel is earlier than 0:1.0.9-51.el4_8
  • AND seamonkey-devel is signed with Red Hat redhatrelease2 key
  • seamonkey-dom-inspector is earlier than 0:1.0.9-51.el4_8
  • AND seamonkey-dom-inspector is signed with Red Hat redhatrelease2 key
  • seamonkey-js-debugger is earlier than 0:1.0.9-51.el4_8
  • AND seamonkey-js-debugger is signed with Red Hat redhatrelease2 key
  • seamonkey-mail is earlier than 0:1.0.9-51.el4_8
  • AND seamonkey-mail is signed with Red Hat redhatrelease2 key
  • BACK