{"id":"openSUSE-SU-2018:2807-1","summary":"Security update for seamonkey","details":"This update for seamonkey fixes the following issues:\n\nMozilla Seamonkey was updated to 2.49.4:\n\nNow uses Gecko 52.9.1esr (boo#1098998).\n\nSecurity issues fixed with MFSA 2018-16 (boo#1098998):\n\n* CVE-2018-12359: Buffer overflow using computed size of canvas element\n* CVE-2018-12360: Use-after-free when using focus()\n* CVE-2018-12362: Integer overflow in SSSE3 scaler\n* CVE-2018-5156: Media recorder segmentation fault when track type is changed during capture\n* CVE-2018-12363: Use-after-free when appending DOM nodes\n* CVE-2018-12364: CSRF attacks through 307 redirects and NPAPI plugins\n* CVE-2018-12365: Compromised IPC child process can list local filenames\n* CVE-2018-12366: Invalid data handling during QCMS transformations\n* CVE-2018-5188: Memory safety bugs fixed in Firefox 60, Firefox ESR 60.1, and Firefox ESR 52.9\n\nLocalizations finally included again (boo#1062195)\n\nUpdated summary and description to more accurately\nreflect what SeaMonkey is, giving less prominence to the long-\ndiscontinued Mozilla Application Suite that many users may no\nlonger be familiar with\n\nUpdate to Seamonkey 2.49.2\n\n* Gecko 52.6esr (including security relevant fixes) (boo#1077291)\n* fix issue in Composer\n* With some themes, the menulist- and history-dropmarker didn't show\n* Scrollbars didn't show the buttons\n* WebRTC has been disabled by default. It needs an add-on to enable it per site\n* The active title bar was not visually emphasized\n\nCorrect requires and provides handling (boo#1076907)\n\nThis update was imported from the openSUSE:Leap:15.0:Update update project.\n","modified":"2026-02-04T02:56:12.307408Z","published":"2018-08-16T07:40:05Z","related":["CVE-2018-12359","CVE-2018-12360","CVE-2018-12362","CVE-2018-12363","CVE-2018-12364","CVE-2018-12365","CVE-2018-12366","CVE-2018-5156","CVE-2018-5188"],"upstream":["CVE-2018-12359","CVE-2018-12360","CVE-2018-12362","CVE-2018-12363","CVE-2018-12364","CVE-2018-12365","CVE-2018-12366","CVE-2018-5156","CVE-2018-5188"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GLUOSK2EJUPHGOY64OTIF2JORV62RASV/#GLUOSK2EJUPHGOY64OTIF2JORV62RASV"},{"type":"REPORT","url":"https://bugzilla.suse.com/1020631"},{"type":"REPORT","url":"https://bugzilla.suse.com/1062195"},{"type":"REPORT","url":"https://bugzilla.suse.com/1076907"},{"type":"REPORT","url":"https://bugzilla.suse.com/1077291"},{"type":"REPORT","url":"https://bugzilla.suse.com/1098998"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12359"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12360"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12362"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12363"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12364"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12365"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12366"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-5156"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-5188"}],"affected":[{"package":{"name":"seamonkey","ecosystem":"SUSE:Package Hub 15","purl":"pkg:rpm/suse/seamonkey&distro=SUSE%20Package%20Hub%2015"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.49.4-bp150.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"seamonkey-translations-common":"2.49.4-bp150.3.3.1","seamonkey-translations-other":"2.49.4-bp150.3.3.1","seamonkey":"2.49.4-bp150.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2018:2807-1.json"}}],"schema_version":"1.7.3"}