Executive Summary

Summary
Titleseamonkey security update
Informations
NameRHSA-2008:1037First vendor Publication2008-12-16
VendorRedHatLast vendor Modification2008-12-16
Severity (Vendor) CriticalRevision01

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score10Attack RangeNetwork
Cvss Impact Score10Attack ComplexityLow
Cvss Expoit Score10AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Problem Description:

Updated seamonkey packages that fix security issues are now available for
Red Hat Enterprise Linux 2.1, Red Hat Enterprise Linux 3, and Red Hat
Enterprise Linux 4.

This update has been rated as having critical security impact by the Red
Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

3. Description:

SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2008-5500, CVE-2008-5501, CVE-2008-5502, CVE-2008-5504, CVE-2008-5511,
CVE-2008-5512, CVE-2008-5513)

Several flaws were found in the way malformed content was processed. A
website containing specially-crafted content could potentially trick a
SeaMonkey user into surrendering sensitive information. (CVE-2008-5503,
CVE-2008-5506, CVE-2008-5507)

A flaw was found in the way malformed URLs were processed by SeaMonkey.
This flaw could prevent various URL sanitization mechanisms from properly
parsing a malicious URL. (CVE-2008-5508)

Note: after the errata packages are installed, SeaMonkey must be restarted
for the update to take effect.

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches to resolve these issues.

4. Solution:

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

5. Package List:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 :

Source:
ftp://updates.redhat.com/enterprise/2.1AS/en/os/SRPMS/seamonkey-1.0.9-0.25.el2.src.rpm

i386:
seamonkey-1.0.9-0.25.el2.i386.rpm
seamonkey-chat-1.0.9-0.25.el2.i386.rpm
seamonkey-devel-1.0.9-0.25.el2.i386.rpm
seamonkey-dom-inspector-1.0.9-0.25.el2.i386.rpm
seamonkey-js-debugger-1.0.9-0.25.el2.i386.rpm
seamonkey-mail-1.0.9-0.25.el2.i386.rpm
seamonkey-nspr-1.0.9-0.25.el2.i386.rpm
seamonkey-nspr-devel-1.0.9-0.25.el2.i386.rpm
seamonkey-nss-1.0.9-0.25.el2.i386.rpm
seamonkey-nss-devel-1.0.9-0.25.el2.i386.rpm

ia64:
seamonkey-1.0.9-0.25.el2.ia64.rpm
seamonkey-chat-1.0.9-0.25.el2.ia64.rpm
seamonkey-devel-1.0.9-0.25.el2.ia64.rpm
seamonkey-dom-inspector-1.0.9-0.25.el2.ia64.rpm
seamonkey-js-debugger-1.0.9-0.25.el2.ia64.rpm
seamonkey-mail-1.0.9-0.25.el2.ia64.rpm
seamonkey-nspr-1.0.9-0.25.el2.ia64.rpm
seamonkey-nspr-devel-1.0.9-0.25.el2.ia64.rpm
seamonkey-nss-1.0.9-0.25.el2.ia64.rpm
seamonkey-nss-devel-1.0.9-0.25.el2.ia64.rpm

Red Hat Linux Advanced Workstation 2.1:

Source:
ftp://updates.redhat.com/enterprise/2.1AW/en/os/SRPMS/seamonkey-1.0.9-0.25.el2.src.rpm

ia64:
seamonkey-1.0.9-0.25.el2.ia64.rpm
seamonkey-chat-1.0.9-0.25.el2.ia64.rpm
seamonkey-devel-1.0.9-0.25.el2.ia64.rpm
seamonkey-dom-inspector-1.0.9-0.25.el2.ia64.rpm
seamonkey-js-debugger-1.0.9-0.25.el2.ia64.rpm
seamonkey-mail-1.0.9-0.25.el2.ia64.rpm
seamonkey-nspr-1.0.9-0.25.el2.ia64.rpm
seamonkey-nspr-devel-1.0.9-0.25.el2.ia64.rpm
seamonkey-nss-1.0.9-0.25.el2.ia64.rpm
seamonkey-nss-devel-1.0.9-0.25.el2.ia64.rpm

Red Hat Enterprise Linux ES version 2.1:

Source:
ftp://updates.redhat.com/enterprise/2.1ES/en/os/SRPMS/seamonkey-1.0.9-0.25.el2.src.rpm

i386:
seamonkey-1.0.9-0.25.el2.i386.rpm
seamonkey-chat-1.0.9-0.25.el2.i386.rpm
seamonkey-devel-1.0.9-0.25.el2.i386.rpm
seamonkey-dom-inspector-1.0.9-0.25.el2.i386.rpm
seamonkey-js-debugger-1.0.9-0.25.el2.i386.rpm
seamonkey-mail-1.0.9-0.25.el2.i386.rpm
seamonkey-nspr-1.0.9-0.25.el2.i386.rpm
seamonkey-nspr-devel-1.0.9-0.25.el2.i386.rpm
seamonkey-nss-1.0.9-0.25.el2.i386.rpm
seamonkey-nss-devel-1.0.9-0.25.el2.i386.rpm

Red Hat Enterprise Linux WS version 2.1:

Source:
ftp://updates.redhat.com/enterprise/2.1WS/en/os/SRPMS/seamonkey-1.0.9-0.25.el2.src.rpm

i386:
seamonkey-1.0.9-0.25.el2.i386.rpm
seamonkey-chat-1.0.9-0.25.el2.i386.rpm
seamonkey-devel-1.0.9-0.25.el2.i386.rpm
seamonkey-dom-inspector-1.0.9-0.25.el2.i386.rpm
seamonkey-js-debugger-1.0.9-0.25.el2.i386.rpm
seamonkey-mail-1.0.9-0.25.el2.i386.rpm
seamonkey-nspr-1.0.9-0.25.el2.i386.rpm
seamonkey-nspr-devel-1.0.9-0.25.el2.i386.rpm
seamonkey-nss-1.0.9-0.25.el2.i386.rpm
seamonkey-nss-devel-1.0.9-0.25.el2.i386.rpm

Red Hat Enterprise Linux AS version 3:

Source:
ftp://updates.redhat.com/enterprise/3AS/en/os/SRPMS/seamonkey-1.0.9-0.29.el3.src.rpm

i386:
seamonkey-1.0.9-0.29.el3.i386.rpm
seamonkey-chat-1.0.9-0.29.el3.i386.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.i386.rpm
seamonkey-devel-1.0.9-0.29.el3.i386.rpm
seamonkey-dom-inspector-1.0.9-0.29.el3.i386.rpm
seamonkey-js-debugger-1.0.9-0.29.el3.i386.rpm
seamonkey-mail-1.0.9-0.29.el3.i386.rpm
seamonkey-nspr-1.0.9-0.29.el3.i386.rpm
seamonkey-nspr-devel-1.0.9-0.29.el3.i386.rpm
seamonkey-nss-1.0.9-0.29.el3.i386.rpm
seamonkey-nss-devel-1.0.9-0.29.el3.i386.rpm

ia64:
seamonkey-1.0.9-0.29.el3.ia64.rpm
seamonkey-chat-1.0.9-0.29.el3.ia64.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.i386.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.ia64.rpm
seamonkey-devel-1.0.9-0.29.el3.ia64.rpm
seamonkey-dom-inspector-1.0.9-0.29.el3.ia64.rpm
seamonkey-js-debugger-1.0.9-0.29.el3.ia64.rpm
seamonkey-mail-1.0.9-0.29.el3.ia64.rpm
seamonkey-nspr-1.0.9-0.29.el3.i386.rpm
seamonkey-nspr-1.0.9-0.29.el3.ia64.rpm
seamonkey-nspr-devel-1.0.9-0.29.el3.ia64.rpm
seamonkey-nss-1.0.9-0.29.el3.i386.rpm
seamonkey-nss-1.0.9-0.29.el3.ia64.rpm
seamonkey-nss-devel-1.0.9-0.29.el3.ia64.rpm

ppc:
seamonkey-1.0.9-0.29.el3.ppc.rpm
seamonkey-chat-1.0.9-0.29.el3.ppc.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.ppc.rpm
seamonkey-devel-1.0.9-0.29.el3.ppc.rpm
seamonkey-dom-inspector-1.0.9-0.29.el3.ppc.rpm
seamonkey-js-debugger-1.0.9-0.29.el3.ppc.rpm
seamonkey-mail-1.0.9-0.29.el3.ppc.rpm
seamonkey-nspr-1.0.9-0.29.el3.ppc.rpm
seamonkey-nspr-devel-1.0.9-0.29.el3.ppc.rpm
seamonkey-nss-1.0.9-0.29.el3.ppc.rpm
seamonkey-nss-devel-1.0.9-0.29.el3.ppc.rpm

s390:
seamonkey-1.0.9-0.29.el3.s390.rpm
seamonkey-chat-1.0.9-0.29.el3.s390.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.s390.rpm
seamonkey-devel-1.0.9-0.29.el3.s390.rpm
seamonkey-dom-inspector-1.0.9-0.29.el3.s390.rpm
seamonkey-js-debugger-1.0.9-0.29.el3.s390.rpm
seamonkey-mail-1.0.9-0.29.el3.s390.rpm
seamonkey-nspr-1.0.9-0.29.el3.s390.rpm
seamonkey-nspr-devel-1.0.9-0.29.el3.s390.rpm
seamonkey-nss-1.0.9-0.29.el3.s390.rpm
seamonkey-nss-devel-1.0.9-0.29.el3.s390.rpm

s390x:
seamonkey-1.0.9-0.29.el3.s390x.rpm
seamonkey-chat-1.0.9-0.29.el3.s390x.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.s390.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.s390x.rpm
seamonkey-devel-1.0.9-0.29.el3.s390x.rpm
seamonkey-dom-inspector-1.0.9-0.29.el3.s390x.rpm
seamonkey-js-debugger-1.0.9-0.29.el3.s390x.rpm
seamonkey-mail-1.0.9-0.29.el3.s390x.rpm
seamonkey-nspr-1.0.9-0.29.el3.s390.rpm
seamonkey-nspr-1.0.9-0.29.el3.s390x.rpm
seamonkey-nspr-devel-1.0.9-0.29.el3.s390x.rpm
seamonkey-nss-1.0.9-0.29.el3.s390.rpm
seamonkey-nss-1.0.9-0.29.el3.s390x.rpm
seamonkey-nss-devel-1.0.9-0.29.el3.s390x.rpm

x86_64:
seamonkey-1.0.9-0.29.el3.i386.rpm
seamonkey-1.0.9-0.29.el3.x86_64.rpm
seamonkey-chat-1.0.9-0.29.el3.x86_64.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.i386.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.x86_64.rpm
seamonkey-devel-1.0.9-0.29.el3.x86_64.rpm
seamonkey-dom-inspector-1.0.9-0.29.el3.x86_64.rpm
seamonkey-js-debugger-1.0.9-0.29.el3.x86_64.rpm
seamonkey-mail-1.0.9-0.29.el3.x86_64.rpm
seamonkey-nspr-1.0.9-0.29.el3.i386.rpm
seamonkey-nspr-1.0.9-0.29.el3.x86_64.rpm
seamonkey-nspr-devel-1.0.9-0.29.el3.x86_64.rpm
seamonkey-nss-1.0.9-0.29.el3.i386.rpm
seamonkey-nss-1.0.9-0.29.el3.x86_64.rpm
seamonkey-nss-devel-1.0.9-0.29.el3.x86_64.rpm

Red Hat Desktop version 3:

Source:
ftp://updates.redhat.com/enterprise/3desktop/en/os/SRPMS/seamonkey-1.0.9-0.29.el3.src.rpm

i386:
seamonkey-1.0.9-0.29.el3.i386.rpm
seamonkey-chat-1.0.9-0.29.el3.i386.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.i386.rpm
seamonkey-devel-1.0.9-0.29.el3.i386.rpm
seamonkey-dom-inspector-1.0.9-0.29.el3.i386.rpm
seamonkey-js-debugger-1.0.9-0.29.el3.i386.rpm
seamonkey-mail-1.0.9-0.29.el3.i386.rpm
seamonkey-nspr-1.0.9-0.29.el3.i386.rpm
seamonkey-nspr-devel-1.0.9-0.29.el3.i386.rpm
seamonkey-nss-1.0.9-0.29.el3.i386.rpm
seamonkey-nss-devel-1.0.9-0.29.el3.i386.rpm

x86_64:
seamonkey-1.0.9-0.29.el3.i386.rpm
seamonkey-1.0.9-0.29.el3.x86_64.rpm
seamonkey-chat-1.0.9-0.29.el3.x86_64.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.i386.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.x86_64.rpm
seamonkey-devel-1.0.9-0.29.el3.x86_64.rpm
seamonkey-dom-inspector-1.0.9-0.29.el3.x86_64.rpm
seamonkey-js-debugger-1.0.9-0.29.el3.x86_64.rpm
seamonkey-mail-1.0.9-0.29.el3.x86_64.rpm
seamonkey-nspr-1.0.9-0.29.el3.i386.rpm
seamonkey-nspr-1.0.9-0.29.el3.x86_64.rpm
seamonkey-nspr-devel-1.0.9-0.29.el3.x86_64.rpm
seamonkey-nss-1.0.9-0.29.el3.i386.rpm
seamonkey-nss-1.0.9-0.29.el3.x86_64.rpm
seamonkey-nss-devel-1.0.9-0.29.el3.x86_64.rpm

Red Hat Enterprise Linux ES version 3:

Source:
ftp://updates.redhat.com/enterprise/3ES/en/os/SRPMS/seamonkey-1.0.9-0.29.el3.src.rpm

i386:
seamonkey-1.0.9-0.29.el3.i386.rpm
seamonkey-chat-1.0.9-0.29.el3.i386.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.i386.rpm
seamonkey-devel-1.0.9-0.29.el3.i386.rpm
seamonkey-dom-inspector-1.0.9-0.29.el3.i386.rpm
seamonkey-js-debugger-1.0.9-0.29.el3.i386.rpm
seamonkey-mail-1.0.9-0.29.el3.i386.rpm
seamonkey-nspr-1.0.9-0.29.el3.i386.rpm
seamonkey-nspr-devel-1.0.9-0.29.el3.i386.rpm
seamonkey-nss-1.0.9-0.29.el3.i386.rpm
seamonkey-nss-devel-1.0.9-0.29.el3.i386.rpm

ia64:
seamonkey-1.0.9-0.29.el3.ia64.rpm
seamonkey-chat-1.0.9-0.29.el3.ia64.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.i386.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.ia64.rpm
seamonkey-devel-1.0.9-0.29.el3.ia64.rpm
seamonkey-dom-inspector-1.0.9-0.29.el3.ia64.rpm
seamonkey-js-debugger-1.0.9-0.29.el3.ia64.rpm
seamonkey-mail-1.0.9-0.29.el3.ia64.rpm
seamonkey-nspr-1.0.9-0.29.el3.i386.rpm
seamonkey-nspr-1.0.9-0.29.el3.ia64.rpm
seamonkey-nspr-devel-1.0.9-0.29.el3.ia64.rpm
seamonkey-nss-1.0.9-0.29.el3.i386.rpm
seamonkey-nss-1.0.9-0.29.el3.ia64.rpm
seamonkey-nss-devel-1.0.9-0.29.el3.ia64.rpm

x86_64:
seamonkey-1.0.9-0.29.el3.i386.rpm
seamonkey-1.0.9-0.29.el3.x86_64.rpm
seamonkey-chat-1.0.9-0.29.el3.x86_64.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.i386.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.x86_64.rpm
seamonkey-devel-1.0.9-0.29.el3.x86_64.rpm
seamonkey-dom-inspector-1.0.9-0.29.el3.x86_64.rpm
seamonkey-js-debugger-1.0.9-0.29.el3.x86_64.rpm
seamonkey-mail-1.0.9-0.29.el3.x86_64.rpm
seamonkey-nspr-1.0.9-0.29.el3.i386.rpm
seamonkey-nspr-1.0.9-0.29.el3.x86_64.rpm
seamonkey-nspr-devel-1.0.9-0.29.el3.x86_64.rpm
seamonkey-nss-1.0.9-0.29.el3.i386.rpm
seamonkey-nss-1.0.9-0.29.el3.x86_64.rpm
seamonkey-nss-devel-1.0.9-0.29.el3.x86_64.rpm

Red Hat Enterprise Linux WS version 3:

Source:
ftp://updates.redhat.com/enterprise/3WS/en/os/SRPMS/seamonkey-1.0.9-0.29.el3.src.rpm

i386:
seamonkey-1.0.9-0.29.el3.i386.rpm
seamonkey-chat-1.0.9-0.29.el3.i386.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.i386.rpm
seamonkey-devel-1.0.9-0.29.el3.i386.rpm
seamonkey-dom-inspector-1.0.9-0.29.el3.i386.rpm
seamonkey-js-debugger-1.0.9-0.29.el3.i386.rpm
seamonkey-mail-1.0.9-0.29.el3.i386.rpm
seamonkey-nspr-1.0.9-0.29.el3.i386.rpm
seamonkey-nspr-devel-1.0.9-0.29.el3.i386.rpm
seamonkey-nss-1.0.9-0.29.el3.i386.rpm
seamonkey-nss-devel-1.0.9-0.29.el3.i386.rpm

ia64:
seamonkey-1.0.9-0.29.el3.ia64.rpm
seamonkey-chat-1.0.9-0.29.el3.ia64.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.i386.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.ia64.rpm
seamonkey-devel-1.0.9-0.29.el3.ia64.rpm
seamonkey-dom-inspector-1.0.9-0.29.el3.ia64.rpm
seamonkey-js-debugger-1.0.9-0.29.el3.ia64.rpm
seamonkey-mail-1.0.9-0.29.el3.ia64.rpm
seamonkey-nspr-1.0.9-0.29.el3.i386.rpm
seamonkey-nspr-1.0.9-0.29.el3.ia64.rpm
seamonkey-nspr-devel-1.0.9-0.29.el3.ia64.rpm
seamonkey-nss-1.0.9-0.29.el3.i386.rpm
seamonkey-nss-1.0.9-0.29.el3.ia64.rpm
seamonkey-nss-devel-1.0.9-0.29.el3.ia64.rpm

x86_64:
seamonkey-1.0.9-0.29.el3.i386.rpm
seamonkey-1.0.9-0.29.el3.x86_64.rpm
seamonkey-chat-1.0.9-0.29.el3.x86_64.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.i386.rpm
seamonkey-debuginfo-1.0.9-0.29.el3.x86_64.rpm
seamonkey-devel-1.0.9-0.29.el3.x86_64.rpm
seamonkey-dom-inspector-1.0.9-0.29.el3.x86_64.rpm
seamonkey-js-debugger-1.0.9-0.29.el3.x86_64.rpm
seamonkey-mail-1.0.9-0.29.el3.x86_64.rpm
seamonkey-nspr-1.0.9-0.29.el3.i386.rpm
seamonkey-nspr-1.0.9-0.29.el3.x86_64.rpm
seamonkey-nspr-devel-1.0.9-0.29.el3.x86_64.rpm
seamonkey-nss-1.0.9-0.29.el3.i386.rpm
seamonkey-nss-1.0.9-0.29.el3.x86_64.rpm
seamonkey-nss-devel-1.0.9-0.29.el3.x86_64.rpm

Red Hat Enterprise Linux AS version 4:

Source:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/seamonkey-1.0.9-32.el4.src.rpm

i386:
seamonkey-1.0.9-32.el4.i386.rpm
seamonkey-chat-1.0.9-32.el4.i386.rpm
seamonkey-debuginfo-1.0.9-32.el4.i386.rpm
seamonkey-devel-1.0.9-32.el4.i386.rpm
seamonkey-dom-inspector-1.0.9-32.el4.i386.rpm
seamonkey-js-debugger-1.0.9-32.el4.i386.rpm
seamonkey-mail-1.0.9-32.el4.i386.rpm

ia64:
seamonkey-1.0.9-32.el4.ia64.rpm
seamonkey-chat-1.0.9-32.el4.ia64.rpm
seamonkey-debuginfo-1.0.9-32.el4.ia64.rpm
seamonkey-devel-1.0.9-32.el4.ia64.rpm
seamonkey-dom-inspector-1.0.9-32.el4.ia64.rpm
seamonkey-js-debugger-1.0.9-32.el4.ia64.rpm
seamonkey-mail-1.0.9-32.el4.ia64.rpm

ppc:
seamonkey-1.0.9-32.el4.ppc.rpm
seamonkey-chat-1.0.9-32.el4.ppc.rpm
seamonkey-debuginfo-1.0.9-32.el4.ppc.rpm
seamonkey-devel-1.0.9-32.el4.ppc.rpm
seamonkey-dom-inspector-1.0.9-32.el4.ppc.rpm
seamonkey-js-debugger-1.0.9-32.el4.ppc.rpm
seamonkey-mail-1.0.9-32.el4.ppc.rpm

s390:
seamonkey-1.0.9-32.el4.s390.rpm
seamonkey-chat-1.0.9-32.el4.s390.rpm
seamonkey-debuginfo-1.0.9-32.el4.s390.rpm
seamonkey-devel-1.0.9-32.el4.s390.rpm
seamonkey-dom-inspector-1.0.9-32.el4.s390.rpm
seamonkey-js-debugger-1.0.9-32.el4.s390.rpm
seamonkey-mail-1.0.9-32.el4.s390.rpm

s390x:
seamonkey-1.0.9-32.el4.s390x.rpm
seamonkey-chat-1.0.9-32.el4.s390x.rpm
seamonkey-debuginfo-1.0.9-32.el4.s390x.rpm
seamonkey-devel-1.0.9-32.el4.s390x.rpm
seamonkey-dom-inspector-1.0.9-32.el4.s390x.rpm
seamonkey-js-debugger-1.0.9-32.el4.s390x.rpm
seamonkey-mail-1.0.9-32.el4.s390x.rpm

x86_64:
seamonkey-1.0.9-32.el4.x86_64.rpm
seamonkey-chat-1.0.9-32.el4.x86_64.rpm
seamonkey-debuginfo-1.0.9-32.el4.x86_64.rpm
seamonkey-devel-1.0.9-32.el4.x86_64.rpm
seamonkey-dom-inspector-1.0.9-32.el4.x86_64.rpm
seamonkey-js-debugger-1.0.9-32.el4.x86_64.rpm
seamonkey-mail-1.0.9-32.el4.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

Source:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/seamonkey-1.0.9-32.el4.src.rpm

i386:
seamonkey-1.0.9-32.el4.i386.rpm
seamonkey-chat-1.0.9-32.el4.i386.rpm
seamonkey-debuginfo-1.0.9-32.el4.i386.rpm
seamonkey-devel-1.0.9-32.el4.i386.rpm
seamonkey-dom-inspector-1.0.9-32.el4.i386.rpm
seamonkey-js-debugger-1.0.9-32.el4.i386.rpm
seamonkey-mail-1.0.9-32.el4.i386.rpm

x86_64:
seamonkey-1.0.9-32.el4.x86_64.rpm
seamonkey-chat-1.0.9-32.el4.x86_64.rpm
seamonkey-debuginfo-1.0.9-32.el4.x86_64.rpm
seamonkey-devel-1.0.9-32.el4.x86_64.rpm
seamonkey-dom-inspector-1.0.9-32.el4.x86_64.rpm
seamonkey-js-debugger-1.0.9-32.el4.x86_64.rpm
seamonkey-mail-1.0.9-32.el4.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

Source:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/seamonkey-1.0.9-32.el4.src.rpm

i386:
seamonkey-1.0.9-32.el4.i386.rpm
seamonkey-chat-1.0.9-32.el4.i386.rpm
seamonkey-debuginfo-1.0.9-32.el4.i386.rpm
seamonkey-devel-1.0.9-32.el4.i386.rpm
seamonkey-dom-inspector-1.0.9-32.el4.i386.rpm
seamonkey-js-debugger-1.0.9-32.el4.i386.rpm
seamonkey-mail-1.0.9-32.el4.i386.rpm

ia64:
seamonkey-1.0.9-32.el4.ia64.rpm
seamonkey-chat-1.0.9-32.el4.ia64.rpm
seamonkey-debuginfo-1.0.9-32.el4.ia64.rpm
seamonkey-devel-1.0.9-32.el4.ia64.rpm
seamonkey-dom-inspector-1.0.9-32.el4.ia64.rpm
seamonkey-js-debugger-1.0.9-32.el4.ia64.rpm
seamonkey-mail-1.0.9-32.el4.ia64.rpm

x86_64:
seamonkey-1.0.9-32.el4.x86_64.rpm
seamonkey-chat-1.0.9-32.el4.x86_64.rpm
seamonkey-debuginfo-1.0.9-32.el4.x86_64.rpm
seamonkey-devel-1.0.9-32.el4.x86_64.rpm
seamonkey-dom-inspector-1.0.9-32.el4.x86_64.rpm
seamonkey-js-debugger-1.0.9-32.el4.x86_64.rpm
seamonkey-mail-1.0.9-32.el4.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

Source:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/seamonkey-1.0.9-32.el4.src.rpm

i386:
seamonkey-1.0.9-32.el4.i386.rpm
seamonkey-chat-1.0.9-32.el4.i386.rpm
seamonkey-debuginfo-1.0.9-32.el4.i386.rpm
seamonkey-devel-1.0.9-32.el4.i386.rpm
seamonkey-dom-inspector-1.0.9-32.el4.i386.rpm
seamonkey-js-debugger-1.0.9-32.el4.i386.rpm
seamonkey-mail-1.0.9-32.el4.i386.rpm

ia64:
seamonkey-1.0.9-32.el4.ia64.rpm
seamonkey-chat-1.0.9-32.el4.ia64.rpm
seamonkey-debuginfo-1.0.9-32.el4.ia64.rpm
seamonkey-devel-1.0.9-32.el4.ia64.rpm
seamonkey-dom-inspector-1.0.9-32.el4.ia64.rpm
seamonkey-js-debugger-1.0.9-32.el4.ia64.rpm
seamonkey-mail-1.0.9-32.el4.ia64.rpm

x86_64:
seamonkey-1.0.9-32.el4.x86_64.rpm
seamonkey-chat-1.0.9-32.el4.x86_64.rpm
seamonkey-debuginfo-1.0.9-32.el4.x86_64.rpm
seamonkey-devel-1.0.9-32.el4.x86_64.rpm
seamonkey-dom-inspector-1.0.9-32.el4.x86_64.rpm
seamonkey-js-debugger-1.0.9-32.el4.x86_64.rpm
seamonkey-mail-1.0.9-32.el4.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://www.redhat.com/security/team/key/#package

Original Source

Url : https://rhn.redhat.com/errata/RHSA-2008-1037.html

CWE : Common Weakness Enumeration

idName
CWE-264Permissions, Privileges, and Access Controls
CWE-399Resource Management Errors
CWE-79Failure to Preserve Web Page Structure ('Cross-site Scripting')
CWE-200Information Exposure
CWE-20Improper Input Validation

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:11053
 
Oval ID: oval:org.mitre.oval:def:11053
Title: The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to (1) a reachable assertion or (2) an integer overflow.
Description: The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to (1) a reachable assertion or (2) an integer overflow.
Family: unix Class: vulnerability
Reference(s): CVE-2008-5500
Version: 5
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:10257
 
Oval ID: oval:org.mitre.oval:def:10257
Title: The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service via vectors that trigger an assertion failure.
Description: The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service via vectors that trigger an assertion failure.
Family: unix Class: vulnerability
Reference(s): CVE-2008-5501
Version: 5
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:10001
 
Oval ID: oval:org.mitre.oval:def:10001
Title: The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.
Description: The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.
Family: unix Class: vulnerability
Reference(s): CVE-2008-5502
Version: 5
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:11423
 
Oval ID: oval:org.mitre.oval:def:11423
Title: The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.
Description: The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.
Family: unix Class: vulnerability
Reference(s): CVE-2008-5503
Version: 5
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:10781
 
Oval ID: oval:org.mitre.oval:def:10781
Title: Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.
Description: Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.
Family: unix Class: vulnerability
Reference(s): CVE-2008-5504
Version: 5
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:10512
 
Oval ID: oval:org.mitre.oval:def:10512
Title: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy by causing the browser to issue an XMLHttpRequest to an attacker-controlled resource that uses a 302 redirect to a resource in a different domain, then reading content from the response, aka "response disclosure."
Description: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy by causing the browser to issue an XMLHttpRequest to an attacker-controlled resource that uses a 302 redirect to a resource in a different domain, then reading content from the response, aka "response disclosure."
Family: unix Class: vulnerability
Reference(s): CVE-2008-5506
Version: 5
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:9376
 
Oval ID: oval:org.mitre.oval:def:9376
Title: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.
Description: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.
Family: unix Class: vulnerability
Reference(s): CVE-2008-5507
Version: 6
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:11040
 
Oval ID: oval:org.mitre.oval:def:11040
Title: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse URLs with leading whitespace or control characters, which might allow remote attackers to misrepresent URLs and simplify phishing attacks.
Description: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse URLs with leading whitespace or control characters, which might allow remote attackers to misrepresent URLs and simplify phishing attacks.
Family: unix Class: vulnerability
Reference(s): CVE-2008-5508
Version: 5
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:11881
 
Oval ID: oval:org.mitre.oval:def:11881
Title: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and conduct cross-site scripting (XSS) attacks via an XBL binding to an "unloaded document."
Description: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and conduct cross-site scripting (XSS) attacks via an XBL binding to an "unloaded document."
Family: unix Class: vulnerability
Reference(s): CVE-2008-5511
Version: 5
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:9814
 
Oval ID: oval:org.mitre.oval:def:9814
Title: Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to run arbitrary JavaScript with chrome privileges via unknown vectors in which "page content can pollute XPCNativeWrappers."
Description: Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to run arbitrary JavaScript with chrome privileges via unknown vectors in which "page content can pollute XPCNativeWrappers."
Family: unix Class: vulnerability
Reference(s): CVE-2008-5512
Version: 5
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:10389
 
Oval ID: oval:org.mitre.oval:def:10389
Title: Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote attackers to bypass the same origin policy, inject content into documents associated with other domains, and conduct cross-site scripting (XSS) attacks via unknown vectors related to restoration of SessionStore data.
Description: Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote attackers to bypass the same origin policy, inject content into documents associated with other domains, and conduct cross-site scripting (XSS) attacks via unknown vectors related to restoration of SessionStore data.
Family: unix Class: vulnerability
Reference(s): CVE-2008-5513
Version: 5
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application24
Application25
Application10

Open Source Vulnerability Database (OSVDB)

idDescription
51297Mozilla Firefox session-restore Data Restoration Same-origin Policy Bypass
51296Mozilla Multiple Products XPCNativeWrappers Pollution JavaScript Privilege Es...
51295Mozilla Multiple Products XBL Binding Unloaded Document XSS
51293Mozilla Multiple Products Whitespace / Control Character URL Handling Phishin...
51292Mozilla Multiple Products window.onerror DOM API Same-origin Policy Bypass In...
51291Mozilla Multiple Products XMLHttpRequest 302 Redirect Same-origin Policy Bypa...
51289Mozilla Firefox Feed Preview JavaScript Privilege Escalation
51288Mozilla Multiple Product loadBindingDocument Function XBL Binding Same-domain...
51287Mozilla Multiple Products Layout Engine FastAppendChar Function Memory Corrup...
51286Mozilla Multiple Products Layout Engine Assertion Failure Remote DoS
51285Mozilla Multiple Products Layout Engine nsEscapeHTML2 Overflow
51284Mozilla Multiple Products Layout Engine PresShell::InitialReflow XUL iframe O...