Summary
The host is installed with Mozilla Seamonkey, that is prone to multiple vulnerabilities.
Impact
Successful exploitation could result in remote arbitrary code execution, spoofing attacks, sensitive information disclosure, and JavaScript code can execute with the privileges of JAR's signer.
Impact Level: System
Solution
Upgrade to Seamonkey version 1.1.10 or later
http://www.seamonkey-project.org/releases/
Insight
Issues are due to,
- multiple errors in the layout and JavaScript engines that can corrupt memory.
- error while handling unprivileged XUL documents that can be exploited to load chrome scripts from a fastload file via <script> elements.
- error in mozIJSSubScriptLoader.LoadScript function can bypass XPCNativeWrappers.
- error in block re-flow process, which can potentially lead to crash.
- error in processing file URLs contained within local directory listings.
- errors in the implementation of the Javascript same origin policy - errors in the verification of signed JAR files.
- improper implementation of file upload forms result in uploading specially crafted DOM Range and originalTarget elements.
- error in Java LiveConnect implementation.
- error in processing of Alt Names provided by peer.
- error in processing of windows URL shortcuts.
Affected
Seamonkey version prior to 1.1.10 on Windows.
References
- http://www.mozilla.org/security/announce/2008/mfsa2008-21.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-22.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-23.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-24.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-25.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-27.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-28.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-29.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-30.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-31.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-32.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-33.html
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2008-2798, CVE-2008-2799, CVE-2008-2800, CVE-2008-2801, CVE-2008-2802, CVE-2008-2803, CVE-2008-2805, CVE-2008-2806, CVE-2008-2807, CVE-2008-2808, CVE-2008-2809, CVE-2008-2810, CVE-2008-2811 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Adobe Acrobat Multiple Unspecified Vulnerabilities-01 Sep13 (Windows)
- 7T Interactive Graphical SCADA System Multiple Security Vulnerabilities
- Adobe Acrobat Multiple Vulnerabilities - 01 May14 (Windows)
- Adobe Acrobat Multiple Vulnerabilities-01 Dec14 (Mac OS X)
- Adobe Air Multiple Vulnerabilities June-2012 (Windows)