SeaMonkey 1.1.11 Security Release

News, happenings
Post Reply
Message
Author
User avatar
Greatnessguru
Posts: 106
Joined: Mon 09 Jul 2007, 21:07
Location: rural McBain MI USA (near Cadillac MI)
Contact:

SeaMonkey 1.1.11 Security Release

#1 Post by Greatnessguru »

SeaMonkey 1.1.11 Security Release
http://www.seamonkey-project.org/
"Project News
July 15, 2008
SeaMonkey 1.1.11 Security Release
Today, the SeaMonkey project released a
new version of its all-in-one internet suite.
SeaMonkey 1.1.11 closes
several security vulnerabilities and fixes
several smaller problems found in
previous versions."

"several security vulnerabilities":

"Fixed in SeaMonkey 1.1.11
MFSA 2008-34 Remote code execution by overflowing CSS reference counter

"Fixed in SeaMonkey 1.1.10
MFSA 2008-33 Crash and remote code execution in block reflow
MFSA 2008-32 Remote site run as local file via Windows URL shortcut
MFSA 2008-31 Peer-trusted certs can use alt names to spoof
MFSA 2008-30 File location URL in directory listings not escaped properly
MFSA 2008-29 Faulty .properties file results in uninitialized memory being used
MFSA 2008-28 Arbitrary socket connections with Java LiveConnect on Mac OS X
MFSA 2008-27 Arbitrary file upload via originalTarget and DOM Range
MFSA 2008-25 Arbitrary code execution in mozIJSSubScriptLoader.loadSubScript()
MFSA 2008-24 Chrome script loading from fastload file
MFSA 2008-23 Signed JAR tampering
MFSA 2008-22 XSS through JavaScript same-origin violation
MFSA 2008-21 Crashes with evidence of memory corruption (rv:1.8.1.15)
MFSA 2008-20 Crash in JavaScript garbage collector

"Fixed in SeaMonkey 1.1.9
MFSA 2008-19 XUL popup spoofing variant (cross-tab popups)
MFSA 2008-18 Java socket connection to any local port via LiveConnect
MFSA 2008-17 Privacy issue with SSL Client Authentication
MFSA 2008-16 HTTP Referrer spoofing with malformed URLs
MFSA 2008-15 Crashes with evidence of memory corruption (rv:1.8.1.13)
MFSA 2008-14 JavaScript privilege escalation and arbitrary code execution"

###,
Eddie Maddox
Inwood IA USA

User avatar
markofkane
Posts: 310
Joined: Thu 03 Jul 2008, 09:02
Location: Kane, IL USA

#2 Post by markofkane »

how does one install updated Seamonkey, without breaking Gxine?

If I'm going to update, I don't want to keep the old version.

Caneri
Posts: 1513
Joined: Tue 04 Sep 2007, 13:23
Location: Canada

#3 Post by Caneri »

Hi Greatnessguru,

This is slightly off topic but I have a question about Seamonkey.

Is there any way to get the personal toolbar to accept dragged and dropped links from the nav bar?

Also is there a way to clear private data (cookies,history,cache etc) on closing Seamonkey (like FF can do).

If I can get these two issues solved I will use Seamonkey full time. Firefox seems to have issues with crashes and cpu usage in Puppy and my wife even says there is an issue in XP...hmmm.

Thanks,
Eric
[color=darkred][i]Be not afraid to grow slowly, only be afraid of standing still.[/i]
Chinese Proverb[/color]

User avatar
Colonel Panic
Posts: 2171
Joined: Sat 16 Sep 2006, 11:09

#4 Post by Colonel Panic »

Thanks for this thread. I've downloaded and installed Seamonkey and it seems to work well.

nooby
Posts: 10369
Joined: Sun 29 Jun 2008, 19:05
Location: SwedenEurope

#5 Post by nooby »

I downloaded it and installed it and works good.

But one of the page me want to look at requires java.

http://www.stormtracker.se/

I went here http://java.com/en/download/linux_manua ... ava.com:80

But being a noob I don't know which linux me should use and how.

Could anybody explain?

User avatar
trapster
Posts: 2117
Joined: Mon 28 Nov 2005, 23:14
Location: Maine, USA
Contact:

#6 Post by trapster »

Is there any way to get the personal toolbar to accept dragged and dropped links from the nav bar?



See Here
trapster
Maine, USA

Asus eeepc 1005HA PU1X-BK
Frugal install: Slacko
Currently using full install: DebianDog

User avatar
nitehawk
Posts: 658
Joined: Sun 13 Apr 2008, 22:30
Location: West Central Florida

#7 Post by nitehawk »

nooby,..I just went to that "strormtracker" site with the old Seamonkey,....and it loaded and looked just fine (couldn't READ a word of it, though,...) :)
I'm downloading the new Seamonkey right now,....(whilst I post)....

Caneri
Posts: 1513
Joined: Tue 04 Sep 2007, 13:23
Location: Canada

#8 Post by Caneri »

@trapster,

Thanks for that....I never used Seamonkey much but with all the browser hopping it's just getting to be a pain and Puppy comes with Seamonkey so let's give 'er.

Seamonkey does render page well so with the personal toolbar working and (if) the clear private data will work I will stop the browser wars now and move on to a decent Seamonkey...and yes I know but FF is getting to be a pain and we all have better things to do.

I like Opera but it makes a mess of my server directories and I'm done fighting with it.

Thanks again Trapster..now to clear the cache on auto?....

Best,
Eric
[color=darkred][i]Be not afraid to grow slowly, only be afraid of standing still.[/i]
Chinese Proverb[/color]

User avatar
trapster
Posts: 2117
Joined: Mon 28 Nov 2005, 23:14
Location: Maine, USA
Contact:

#9 Post by trapster »

Try Here to clear the cache. I believe it's putting the folder into a tmp or ram directory that gets cleared on every boot.
trapster
Maine, USA

Asus eeepc 1005HA PU1X-BK
Frugal install: Slacko
Currently using full install: DebianDog

nooby
Posts: 10369
Joined: Sun 29 Jun 2008, 19:05
Location: SwedenEurope

#10 Post by nooby »

Javascript and java isn't the same is it?

One can activate the built in javascipt feature in FireFox
without having an 18 MB java installed? I have java actibated in
Seamonkey and it still fails.

But the stormtracker site takes me here

http://java.com/en/download/linux_manua ... ava.com:80

Do I really have to chose amng them? shouldn't I actibate a Puppy repo
to get a java that Barry tested to work for seamonkey? How do I do such?

I manged to set up mail.gmx.com in seamonkey but fail to send.
Must have missed something obvious? Any suggestion?

nooby
Posts: 10369
Joined: Sun 29 Jun 2008, 19:05
Location: SwedenEurope

#11 Post by nooby »

Yes when one know it is super easy. One do right click and at bottom
there is NoScript and their one allow gmx.com so easy but to a noob like
me very unlikely. I looked in preferences and security.

When I upgraded to seamonkey 1.1.10 then I seems to have lost
ability to play music on youtube. Or doesn't this version have that.

Barry maybe included it in the original and now one need to add it
by hand?

User avatar
alienjeff
Posts: 2265
Joined: Sat 08 Jul 2006, 20:19
Location: Winsted, CT - USA

#12 Post by alienjeff »

Caneri wrote:Firefox seems to have issues with crashes and cpu usage in Puppy and my wife even says there is an issue in XP...hmmm.
What versions of Firefox and Puppy?
[size=84][i]hangout:[/i] ##b0rked on irc.freenode.net
[i]diversion:[/i] [url]http://alienjeff.net[/url] - visit The Fringe
[i]quote:[/i] "The foundation of authority is based upon the consent of the people." - Thomas Hooker[/size]

Caneri
Posts: 1513
Joined: Tue 04 Sep 2007, 13:23
Location: Canada

#13 Post by Caneri »

Hi Jeff,

I just tried posting a long reply and lost it to the internet gods..grrr...let's try this post then I can edit.

Anyway hope you are well old boy...

Best,
Eric
[color=darkred][i]Be not afraid to grow slowly, only be afraid of standing still.[/i]
Chinese Proverb[/color]

Post Reply