Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Debian: DSA-2295-1 Moderate: Iceape Remote Code Execution Risk Details

debian
Calendar Grey August 17, 2011
Scroller Debian
Multiple security weaknesses identified in Iceape pose risks of remote code execution. Critical updates advised for all users.
Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey: CVE-2011-0084

Summary

Several vulnerabilities have been found in the Iceape internet suite, an
unbranded version of Seamonkey:

CVE-2011-0084

"regenrecht" discovered that incorrect pointer handling in the SVG
processing code could lead to the execution of arbitrary code.

CVE-2011-2378

"regenrecht" discovered that incorrect memory management in DOM
processing could lead to the execution of arbitrary code.

CVE-2011-2981

"moz_bug_r_a_4" discovered a Chrome privilege escalation
vulnerability in the event handler code.

CVE-2011-2982

Gary Kwong, Igor Bukanov, Nils and Bob Clary discovered memory
corruption bugs, which may lead to the execution of arbitrary code.

CVE-2011-2983

"shutdown" discovered an information leak in the handling of
RegExp.input.

CVE-2011-2984

"moz_bug_r_a4" discovered a Chrome privilege escalation
vulnerability.

The oldstable distribution (lenny) is not affected. The iceape
package only provides the XPCOM code.

For the stable distribution (squeeze), this problem has been fix...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: iceape
CVE ID: CVE-2011-0084 CVE-2011-2378 CVE-2011-2981 CVE-2011-2982

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.