• [SECURITY] [DSA 2513-1] iceape security update

    From Nico Golde@1:229/2 to All on Tue Jul 17 22:00:02 2012
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2513-1 [email protected] http://www.debian.org/security/ Nico Golde
    July 17, 2012 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : iceape
    Vulnerability : several
    Problem type : remote
    Debian-specific: no
    CVE ID : CVE-2012-1948 CVE-2012-1954 CVE-2012-1967

    Several vulnerabilities have been found in the Iceape internet suite,
    an unbranded version of Seamonkey:

    CVE-2012-1948

    Benoit Jacob, Jesse Ruderman, Christian Holler, and Bill McCloskey
    identified several memory safety problems that may lead to the
    execution of arbitrary code.

    CVE-2012-1954

    Abhishek Arya discovered a use-after-free problem in nsDocument::AdoptNode
    that may lead to the execution of arbitrary code.

    CVE-2012-1967

    moz_bug_r_a4 discovered that in certain cases, javascript:: URLs can
    be executed so that scripts can escape the JavaScript sandbox and run
    with elevated privileges. This can lead to arbitrary code execution.

    For the stable distribution (squeeze), this problem has been fixed in
    version 2.0.11-14.

    For the unstable (sid) and testing (wheezy) distribution, this problem
    will be fixed soon.


    We recommend that you upgrade your iceape packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.12 (GNU/Linux)

    iEYEARECAAYFAlAFwWUACgkQHYflSXNkfP/3tgCgt4oQOinjMBRdwqUdRjuVc6MZ y68An3iRIUYD6qiE/qh0tYs/d+BDVeqb
    =pR7b
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)