[RedHat] Mehrere Schwachstellen in Mozilla Seamonkey bis Version 1.0.9 - RHSA-2010:0967-01

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1

Liebe Kolleginnen und Kollegen,

soeben erreichte uns nachfolgendes RedHat Security Advisory. Wir geben
diese Informationen unveraendert an Sie weiter.

Seamonkey verwendet die Mozilla Browser-Engine.

CVE-2010-3775 – Umgehen von Zugriffskontrollen in der Mozilla
Browser-Engine

Die Mozilla Browser-Engine in Firefox vor Version 3.6.13 und 3.5.16
sowie SeaMonkey vor Version 2.0.11 enthaelt eine Schwachstelle beim
Laden von Java LiveConnect Scripten. Diese ermoeglicht es entfernten
Angreifern Zugriffskontrollen zu umgehen und so beliebigen Code mit den
Rechten der Anwendung auszufuehren.

CVE-2010-3776 – Manipulation von Speicherinhalten in der Mozilla
Browser-Engine

Die Mozilla Browser-Engine enthaelt verschiedene nicht weiter
beschriebene Fehler, die von einem Angreifer ausgenutzt werden koennen,
um die Anwendung zum Absturz zu bringen oder beliebigen Code mit den
Rechten der Anwendung auszufuehren.

CVE-2010-3772 – Buffer Overflow in der Mozilla Browser-Engine

Eine Schwachstelle in der Mozilla Browser-Engine bei der Verarbeitung
von XUL-Strukturen (XUL tree) sorgt fuer eine falsche Berechnung von
Indizes. Werden diese im Folgenden verwendet, kann ueber Puffergrenzen
hinweg geschrieben werden. Ein Angreifer kann dies ausnutzen um die
Anwendung zum Absturz zu bringen oder beliebigen Code mit den Rechten
der Anwendung auszufuehren.

CVE-2010-3767 – Integer Overflow in der Mozilla Browser-Engine

In der Mozilla Browser-Engine existiert eine Schwachstelle in Bezug auf
JavaScript Arrays. Die Speichergroesse fuer ein Array mit sehr vielen
Eintraegen wird zu klein berechnet, was ein entfernter Angreifer unter
Umstaenden ausnutzen kann, um ueber das Ende des Puffers hinaus zu
schreiben und Speicher zu korrumpieren. Die Ausnutzung dieser
Schwachstelle setzt voraus, dass JavaScript aktiviert ist.

Betroffen sind die folgenden Software Pakete und Plattformen:

Paket seamonkey

Red Hat Enterprise Linux AS version 4 – i386, ia64, ppc, s390, s390x,
x86_64
Red Hat Enterprise Linux Desktop version 4 – i386, x86_64
Red Hat Enterprise Linux ES version 4 – i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 – i386, ia64, x86_64

Vom Hersteller werden ueberarbeitete Pakete zur Verfuegung gestellt.

(c) der deutschen Zusammenfassung bei DFN-CERT Services GmbH; die
Verbreitung, auch auszugsweise, ist nur unter Hinweis auf den Urheber,
DFN-CERT Services GmbH, und nur zu nicht kommerziellen Zwecken
gestattet.

Mit freundlichen Gruessen,
Tilmann Haak

– —
Dipl.-Inform. Tilmann Haak (Incident Response Team)

DFN-CERT Services GmbH, https://www.dfn-cert.de, Phone +49 40 808077-590
Sitz / Register: Hamburg, AG Hamburg, HRB 88805, Ust-IdNr.: DE 232129737
Sachsenstrasse 5, 20097 Hamburg/Germany, CEO: Dr. Klaus-Peter Kossakowski

Automatische Warnmeldungen: https://www.cert.dfn.de/autowarn

– —–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1

=====================================================================
Red Hat Security Advisory

Synopsis: Critical: seamonkey security update
Advisory ID: RHSA-2010:0967-01
Product: Red Hat Enterprise Linux
Advisory URL: https://rhn.redhat.com/errata/RHSA-2010-0967.html
Issue date: 2010-12-09
CVE Names: CVE-2010-3767 CVE-2010-3772 CVE-2010-3775
CVE-2010-3776
=====================================================================

1. Summary:

Updated seamonkey packages that fix several security issues are now
available for Red Hat Enterprise Linux 4.

The Red Hat Security Response Team has rated this update as having critical
security impact. Common Vulnerability Scoring System (CVSS) base scores,
which give detailed severity ratings, are available for each vulnerability
from the CVE links in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 – i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 – i386, x86_64
Red Hat Enterprise Linux ES version 4 – i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 – i386, ia64, x86_64

3. Description:

SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2010-3767, CVE-2010-3772, CVE-2010-3776)

A flaw was found in the way SeaMonkey loaded Java LiveConnect scripts.
Malicious web content could load a Java LiveConnect script in a way that
would result in the plug-in object having elevated privileges, allowing it
to execute Java code with the privileges of the user running SeaMonkey.
(CVE-2010-3775)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.

4. Solution:

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

5. Bugs fixed (http://bugzilla.redhat.com/):

660408 – CVE-2010-3776 Mozilla miscellaneous memory safety hazards (MFSA 2010-74)
660419 – CVE-2010-3772 Mozilla crash and remote code execution using HTML tags inside a XUL tree (MFSA 2010-77)
660422 – CVE-2010-3775 Mozilla Java security bypass from LiveConnect loaded via data: URL meta refresh (MFSA 2010-79)
660431 – CVE-2010-3767 Mozilla integer overflow vulnerability in NewIdArray (MFSA 2010-81)

6. Package List:

Red Hat Enterprise Linux AS version 4:

Source:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/seamonkey-1.0.9-66.el4_8.src.rpm

i386:
seamonkey-1.0.9-66.el4_8.i386.rpm
seamonkey-chat-1.0.9-66.el4_8.i386.rpm
seamonkey-debuginfo-1.0.9-66.el4_8.i386.rpm
seamonkey-devel-1.0.9-66.el4_8.i386.rpm
seamonkey-dom-inspector-1.0.9-66.el4_8.i386.rpm
seamonkey-js-debugger-1.0.9-66.el4_8.i386.rpm
seamonkey-mail-1.0.9-66.el4_8.i386.rpm

ia64:
seamonkey-1.0.9-66.el4_8.ia64.rpm
seamonkey-chat-1.0.9-66.el4_8.ia64.rpm
seamonkey-debuginfo-1.0.9-66.el4_8.ia64.rpm
seamonkey-devel-1.0.9-66.el4_8.ia64.rpm
seamonkey-dom-inspector-1.0.9-66.el4_8.ia64.rpm
seamonkey-js-debugger-1.0.9-66.el4_8.ia64.rpm
seamonkey-mail-1.0.9-66.el4_8.ia64.rpm

ppc:
seamonkey-1.0.9-66.el4_8.ppc.rpm
seamonkey-chat-1.0.9-66.el4_8.ppc.rpm
seamonkey-debuginfo-1.0.9-66.el4_8.ppc.rpm
seamonkey-devel-1.0.9-66.el4_8.ppc.rpm
seamonkey-dom-inspector-1.0.9-66.el4_8.ppc.rpm
seamonkey-js-debugger-1.0.9-66.el4_8.ppc.rpm
seamonkey-mail-1.0.9-66.el4_8.ppc.rpm

s390:
seamonkey-1.0.9-66.el4_8.s390.rpm
seamonkey-chat-1.0.9-66.el4_8.s390.rpm
seamonkey-debuginfo-1.0.9-66.el4_8.s390.rpm
seamonkey-devel-1.0.9-66.el4_8.s390.rpm
seamonkey-dom-inspector-1.0.9-66.el4_8.s390.rpm
seamonkey-js-debugger-1.0.9-66.el4_8.s390.rpm
seamonkey-mail-1.0.9-66.el4_8.s390.rpm

s390x:
seamonkey-1.0.9-66.el4_8.s390x.rpm
seamonkey-chat-1.0.9-66.el4_8.s390x.rpm
seamonkey-debuginfo-1.0.9-66.el4_8.s390x.rpm
seamonkey-devel-1.0.9-66.el4_8.s390x.rpm
seamonkey-dom-inspector-1.0.9-66.el4_8.s390x.rpm
seamonkey-js-debugger-1.0.9-66.el4_8.s390x.rpm
seamonkey-mail-1.0.9-66.el4_8.s390x.rpm

x86_64:
seamonkey-1.0.9-66.el4_8.x86_64.rpm
seamonkey-chat-1.0.9-66.el4_8.x86_64.rpm
seamonkey-debuginfo-1.0.9-66.el4_8.x86_64.rpm
seamonkey-devel-1.0.9-66.el4_8.x86_64.rpm
seamonkey-dom-inspector-1.0.9-66.el4_8.x86_64.rpm
seamonkey-js-debugger-1.0.9-66.el4_8.x86_64.rpm
seamonkey-mail-1.0.9-66.el4_8.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

Source:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/seamonkey-1.0.9-66.el4_8.src.rpm

i386:
seamonkey-1.0.9-66.el4_8.i386.rpm
seamonkey-chat-1.0.9-66.el4_8.i386.rpm
seamonkey-debuginfo-1.0.9-66.el4_8.i386.rpm
seamonkey-devel-1.0.9-66.el4_8.i386.rpm
seamonkey-dom-inspector-1.0.9-66.el4_8.i386.rpm
seamonkey-js-debugger-1.0.9-66.el4_8.i386.rpm
seamonkey-mail-1.0.9-66.el4_8.i386.rpm

x86_64:
seamonkey-1.0.9-66.el4_8.x86_64.rpm
seamonkey-chat-1.0.9-66.el4_8.x86_64.rpm
seamonkey-debuginfo-1.0.9-66.el4_8.x86_64.rpm
seamonkey-devel-1.0.9-66.el4_8.x86_64.rpm
seamonkey-dom-inspector-1.0.9-66.el4_8.x86_64.rpm
seamonkey-js-debugger-1.0.9-66.el4_8.x86_64.rpm
seamonkey-mail-1.0.9-66.el4_8.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

Source:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/seamonkey-1.0.9-66.el4_8.src.rpm

i386:
seamonkey-1.0.9-66.el4_8.i386.rpm
seamonkey-chat-1.0.9-66.el4_8.i386.rpm
seamonkey-debuginfo-1.0.9-66.el4_8.i386.rpm
seamonkey-devel-1.0.9-66.el4_8.i386.rpm
seamonkey-dom-inspector-1.0.9-66.el4_8.i386.rpm
seamonkey-js-debugger-1.0.9-66.el4_8.i386.rpm
seamonkey-mail-1.0.9-66.el4_8.i386.rpm

ia64:
seamonkey-1.0.9-66.el4_8.ia64.rpm
seamonkey-chat-1.0.9-66.el4_8.ia64.rpm
seamonkey-debuginfo-1.0.9-66.el4_8.ia64.rpm
seamonkey-devel-1.0.9-66.el4_8.ia64.rpm
seamonkey-dom-inspector-1.0.9-66.el4_8.ia64.rpm
seamonkey-js-debugger-1.0.9-66.el4_8.ia64.rpm
seamonkey-mail-1.0.9-66.el4_8.ia64.rpm

x86_64:
seamonkey-1.0.9-66.el4_8.x86_64.rpm
seamonkey-chat-1.0.9-66.el4_8.x86_64.rpm
seamonkey-debuginfo-1.0.9-66.el4_8.x86_64.rpm
seamonkey-devel-1.0.9-66.el4_8.x86_64.rpm
seamonkey-dom-inspector-1.0.9-66.el4_8.x86_64.rpm
seamonkey-js-debugger-1.0.9-66.el4_8.x86_64.rpm
seamonkey-mail-1.0.9-66.el4_8.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

Source:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/seamonkey-1.0.9-66.el4_8.src.rpm

i386:
seamonkey-1.0.9-66.el4_8.i386.rpm
seamonkey-chat-1.0.9-66.el4_8.i386.rpm
seamonkey-debuginfo-1.0.9-66.el4_8.i386.rpm
seamonkey-devel-1.0.9-66.el4_8.i386.rpm
seamonkey-dom-inspector-1.0.9-66.el4_8.i386.rpm
seamonkey-js-debugger-1.0.9-66.el4_8.i386.rpm
seamonkey-mail-1.0.9-66.el4_8.i386.rpm

ia64:
seamonkey-1.0.9-66.el4_8.ia64.rpm
seamonkey-chat-1.0.9-66.el4_8.ia64.rpm
seamonkey-debuginfo-1.0.9-66.el4_8.ia64.rpm
seamonkey-devel-1.0.9-66.el4_8.ia64.rpm
seamonkey-dom-inspector-1.0.9-66.el4_8.ia64.rpm
seamonkey-js-debugger-1.0.9-66.el4_8.ia64.rpm
seamonkey-mail-1.0.9-66.el4_8.ia64.rpm

x86_64:
seamonkey-1.0.9-66.el4_8.x86_64.rpm
seamonkey-chat-1.0.9-66.el4_8.x86_64.rpm
seamonkey-debuginfo-1.0.9-66.el4_8.x86_64.rpm
seamonkey-devel-1.0.9-66.el4_8.x86_64.rpm
seamonkey-dom-inspector-1.0.9-66.el4_8.x86_64.rpm
seamonkey-js-debugger-1.0.9-66.el4_8.x86_64.rpm
seamonkey-mail-1.0.9-66.el4_8.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/#package

7. References:

https://www.redhat.com/security/data/cve/CVE-2010-3767.html
https://www.redhat.com/security/data/cve/CVE-2010-3772.html
https://www.redhat.com/security/data/cve/CVE-2010-3775.html
https://www.redhat.com/security/data/cve/CVE-2010-3776.html
https://access.redhat.com/security/updates/classification/#critical

8. Contact:

The Red Hat security contact is . More contact
details at https://www.redhat.com/security/team/contact/

Copyright 2010 Red Hat, Inc.
– —–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.4 (GNU/Linux)

iD8DBQFNAW9bXlSAg2UNWIIRAvPmAJ9yZiQxQ+n8p3wBa/CBjiLbDw9fSwCfcUXS
CXwq2gG6YJ8KVulRjJH6nnU=
=XCbs
– —–END PGP SIGNATURE—–
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2.0.9 (GNU/Linux)

iEYEARECAAYFAk0CRlAACgkQWmhIvjFb90VtPgCfb4hdbnArZVe7bjCiHjyNAiOZ
rMUAn1aSkLvnx0AtjxT2ZMBYeT8v3v5w
=2Qvg
—–END PGP SIGNATURE—–

Nach oben