Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2017:0356-1

Опубликовано: 01 фев. 2017
Источник: suse-cvrf

Описание

Security update for seamonkey

This update for Seamonkey to version 2.46 fixes security issues and bugs.

The following vulnerabilities were fixed:

  • Fix all Gecko related security issues between 43.0.1 and 49.0.2
  • CVE-2016-6354: buffer overrun in flex (boo#990856)

The following non-security changes are included:

  • improve recognition of LANGUAGE env variable (boo#1017174)
  • improve TLS compatibility with certain websites (boo#1021636)
  • Seamonkey now requires NSPR 4.12 and NSS 3.25
  • based on Gecko 49.0.2
  • Chatzilla and DOM Inspector were disabled

Список пакетов

openSUSE Leap 42.1
seamonkey-2.46-9.2
seamonkey-translations-common-2.46-9.2
seamonkey-translations-other-2.46-9.2
openSUSE Leap 42.2
seamonkey-2.46-9.2
seamonkey-translations-common-2.46-9.2
seamonkey-translations-other-2.46-9.2

Описание

Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.


Затронутые продукты
openSUSE Leap 42.1:seamonkey-2.46-9.2
openSUSE Leap 42.1:seamonkey-translations-common-2.46-9.2
openSUSE Leap 42.1:seamonkey-translations-other-2.46-9.2
openSUSE Leap 42.2:seamonkey-2.46-9.2

Ссылки