SeaMonkey VCard Double-Free and "addSelectionListener" Vulnerabilities
SECUNIA ADVISORY ID:
SA20394
VERIFY ADVISORY:
http://secunia.com/advisories/20394/
CRITICAL:
Highly critical
IMPACT:
System access
WHERE:
>From remote
SOFTWARE:
Mozilla SeaMonkey 1.x
http://secunia.com/product/9126/
DESCRIPTION:
Two vulnerabilities have been reported in SeaMonkey, which
potentially can be exploited by malicious people to compromise a
user's system.
1) A double-free error within the processing of large VCards with
invalid base64 characters may be exploited to execute arbitrary
code.
2) An error in the processing of the addSelectionListener when
handling notifications in certain situations can be exploited to
execute arbitrary JavaScript code with escalated privileges.
SOLUTION:
Update to version 1.0.2.
http://www.mozilla.org/projects/seamonkey/
PROVIDED AND/OR DISCOVERED BY:
1) Masatoshi Kimura
2) moz_bug_r_a4
ORIGINAL ADVISORY:
1) http://www.mozilla.org/security/announce/2006/mfsa2006-40.html
2) http://www.mozilla.org/security/announce/2006/mfsa2006-43.html
UserAgent: Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.8.0.4) Gecko/20060508 Firefox/1.5.0.4

