Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian: DSA-2312-1 Critical: Iceape Policy Threats and Fixes

debian
Calendar Grey September 29, 2011
Debian Logo
Important security notice for Debian users regarding several vulnerabilities in Iceape. It is advised to update promptly for heightened security.
Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey: CVE-2011-2372

Summary

Several vulnerabilities have been found in the Iceape internet suite,
an unbranded version of Seamonkey:

CVE-2011-2372

Mariusz Mlynski discovered that websites could open a download
dialog - which has "open" as the default action -, while a user
presses the ENTER key.

CVE-2011-2995

Benjamin Smedberg, Bob Clary and Jesse Ruderman discovered crashes
in the rendering engine, which could lead to the execution of
arbitrary code.

CVE-2011-2998

Mark Kaplan discovered an integer underflow in the javascript
engine, which could lead to the execution of arbitrary code.

CVE-2011-2999

Boris Zbarsky discovered that incorrect handling of the
window.location object could lead to bypasses of the same-origin
policy.

CVE-2011-3000

Ian Graham discovered that multiple Location headers might lead to
CRLF injection.

The oldstable distribution (lenny) is not affected. The iceape package
only provides the XPCOM code.

For the stable distribution (squeeze), this problem has been fixed in
versi...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: iceape
CVE ID: CVE-2011-2372 CVE-2011-2995 CVE-2011-2998 CVE-2011-2999

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here