Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

openSUSE: 2023:0278-1 Critical: SeaMonkey Heap Overflow Addressed

opensuse
Calendar Grey October 2, 2023
Dist Opensuse Esm H88
Significant openSUSE patch for SeaMonkey resolves heap overflow issues and introduces multiple essential improvements and updates.
An update that solves one vulnerability and has two fixes is now available

Description

This update for seamonkey fixes the following issues:

update to SeaMonkey 2.53.17.1

* Upstream libwebp security fix bug 1852749.

* CVE-2023-4863: Heap buffer overflow in libwebp bug 1852649.

* Fix bad string encoded in ansi. l10n fr problem only bug 1847887.

* SeaMonkey 2.53.17 uses the same backend as Firefox and contains the

relevant Firefox 60.8 security fixes.

* SeaMonkey 2.53.17 shares most parts of the mail and news code with

Thunderbird. Please read the Thunderbird 60.8.0 release notes for

specific security fixes in this release.

* Additional important security fixes up to Current Firefox 115.3 and

Thunderbird 115.3 ESR plus many enhancements have been backported. We

will continue to enhance SeaMonkey security in subsequent 2.53.x beta

and release versions as fast as we are able to.

update to SeaMonkey 2.53.17

* Fix macOS Contacts permission request bug 1826719.

* Remove SeaMonkey...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP5:

zypper in -t patch openSUSE-2023-278=1

Package List

- openSUSE Backports SLE-15-SP5 (aarch64 x86_64):

seamonkey-2.53.17.1-bp155.2.3.1

seamonkey-dom-inspector-2.53.17.1-bp155.2.3.1

seamonkey-irc-2.53.17.1-bp155.2.3.1

References

https://www.suse.com/security/cve/CVE-2023-4863.html

https://bugzilla.suse.com/1207332

https://bugzilla.suse.com/1209994

https://bugzilla.suse.com/1213986

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2023:0278-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP5 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here