Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian: DSA-2572-1 Moderate: Iceape Remote Code Execution Threats

debian
Calendar Grey November 4, 2012
Debian Logo
Uncover insights on Debian Security Advisory DSA-2572-1 touching upon vulnerabilities concerning Iceape alongside suggested updates.
Several vulnerabilities have been discovered in Iceape, an internet suite based on Seamonkey: CVE-2012-3982

Summary

CVE-2012-3982
Multiple unspecified vulnerabilities in the browser engine
allow remote attackers to cause a denial of service (memory
corruption and application crash) or possibly execute
arbitrary code via unknown vectors.

CVE-2012-3986
Icedove does not properly restrict calls to DOMWindowUtils
methods, which allows remote attackers to bypass intended
access restrictions via crafted JavaScript code.

CVE-2012-3990
A Use-after-free vulnerability in the IME State Manager
implementation allows remote attackers to execute arbitrary
code via unspecified vectors, related to the
nsIContent::GetNameSpaceID function.

CVE-2012-3991
Icedove does not properly restrict JSAPI access to the
GetProperty function, which allows remote attackers to bypass
the Same Origin Policy and possibly have unspecified other
impact via a crafted web site.

CVE-2012-4179
A use-after-free vulnerability in the
...

Read the Full Advisory

Package: iceape
CVE ID: CVE-2012-3982 CVE-2012-3986 CVE-2012-3990 CVE-2012-3991

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here