Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.60862
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1534-1)
Summary:The remote host is missing an update for the Debian 'iceape' package(s) announced via the DSA-1534-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'iceape' package(s) announced via the DSA-1534-1 advisory.

Vulnerability Insight:
Several remote vulnerabilities have been discovered in the Iceape internet suite, an unbranded version of the Seamonkey Internet Suite. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2007-4879

Peter Brodersen and Alexander Klink discovered that the autoselection of SSL client certificates could lead to users being tracked, resulting in a loss of privacy.

CVE-2008-1233

moz_bug_r_a4 discovered that variants of CVE-2007-3738 and CVE-2007-5338 allow the execution of arbitrary code through XPCNativeWrapper.

CVE-2008-1234

moz_bug_r_a4 discovered that insecure handling of event handlers could lead to cross-site scripting.

CVE-2008-1235

Boris Zbarsky, Johnny Stenback and moz_bug_r_a4 discovered that incorrect principal handling could lead to cross-site scripting and the execution of arbitrary code.

CVE-2008-1236

Tom Ferris, Seth Spitzer, Martin Wargers, John Daggett and Mats Palmgren discovered crashes in the layout engine, which might allow the execution of arbitrary code.

CVE-2008-1237

georgi, tgirmann and Igor Bukanov discovered crashes in the Javascript engine, which might allow the execution of arbitrary code.

CVE-2008-1238

Gregory Fleischer discovered that HTTP Referrer headers were handled incorrectly in combination with URLs containing Basic Authentication credentials with empty usernames, resulting in potential Cross-Site Request Forgery attacks.

CVE-2008-1240

Gregory Fleischer discovered that web content fetched through the jar: protocol can use Java to connect to arbitrary ports. This is only an issue in combination with the non-free Java plugin.

CVE-2008-1241

Chris Thomas discovered that background tabs could generate XUL popups overlaying the current tab, resulting in potential spoofing attacks.

The Mozilla products from the old stable distribution (sarge) are no longer supported.

For the stable distribution (etch), these problems have been fixed in version 1.0.13~
pre080323b-0etch1.

We recommend that you upgrade your iceape packages.

Affected Software/OS:
'iceape' package(s) on Debian 4.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-3738
1018414
http://www.securitytracker.com/id?1018414
103177
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103177-1
20070701-01-P
ftp://patches.sgi.com/support/free/security/advisories/20070701-01-P.asc
20070720 rPSA-2007-0148-1 firefox thunderbird
http://www.securityfocus.com/archive/1/474226/100/0/threaded
20070724 FLEA-2007-0033-1: firefox thunderbird
http://www.securityfocus.com/archive/1/474542/100/0/threaded
201516
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1
24946
http://www.securityfocus.com/bid/24946
25589
http://secunia.com/advisories/25589
26072
http://secunia.com/advisories/26072
26095
http://secunia.com/advisories/26095
26103
http://secunia.com/advisories/26103
26106
http://secunia.com/advisories/26106
26107
http://secunia.com/advisories/26107
26149
http://secunia.com/advisories/26149
26151
http://secunia.com/advisories/26151
26159
http://secunia.com/advisories/26159
26179
http://secunia.com/advisories/26179
26204
http://secunia.com/advisories/26204
26205
http://secunia.com/advisories/26205
26211
http://secunia.com/advisories/26211
26216
http://secunia.com/advisories/26216
26258
http://secunia.com/advisories/26258
26271
http://secunia.com/advisories/26271
26460
http://secunia.com/advisories/26460
28135
http://secunia.com/advisories/28135
ADV-2007-2564
http://www.vupen.com/english/advisories/2007/2564
ADV-2007-4256
http://www.vupen.com/english/advisories/2007/4256
DSA-1337
http://www.debian.org/security/2007/dsa-1337
DSA-1338
http://www.debian.org/security/2007/dsa-1338
DSA-1339
http://www.debian.org/security/2007/dsa-1339
GLSA-200708-09
http://www.gentoo.org/security/en/glsa/glsa-200708-09.xml
HPSBUX02153
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
MDKSA-2007:152
http://www.mandriva.com/security/advisories?name=MDKSA-2007:152
RHSA-2007:0722
http://www.redhat.com/support/errata/RHSA-2007-0722.html
RHSA-2007:0723
http://www.redhat.com/support/errata/RHSA-2007-0723.html
RHSA-2007:0724
http://www.redhat.com/support/errata/RHSA-2007-0724.html
SSRT061181
SUSE-SA:2007:049
http://www.novell.com/linux/security/advisories/2007_49_mozilla.html
SUSE-SA:2007:057
http://www.novell.com/linux/security/advisories/2007_57_mozilla.html
USN-490-1
http://www.ubuntu.com/usn/usn-490-1
firefox-xpcnativewrapper-code-execution(35460)
https://exchange.xforce.ibmcloud.com/vulnerabilities/35460
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt
http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html
http://www.mozilla.org/security/announce/2007/mfsa2007-25.html
oval:org.mitre.oval:def:9875
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9875
Common Vulnerability Exposure (CVE) ID: CVE-2007-4879
BugTraq ID: 28448
http://www.securityfocus.com/bid/28448
Bugtraq: 20080327 rPSA-2008-0128-1 firefox (Google Search)
http://www.securityfocus.com/archive/1/490196/100/0/threaded
Cert/CC Advisory: TA08-087A
http://www.us-cert.gov/cas/techalerts/TA08-087A.html
Debian Security Information: DSA-1532 (Google Search)
http://www.debian.org/security/2008/dsa-1532
Debian Security Information: DSA-1534 (Google Search)
http://www.debian.org/security/2008/dsa-1534
Debian Security Information: DSA-1535 (Google Search)
http://www.debian.org/security/2008/dsa-1535
http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:080
http://0x90.eu/ff_tls_poc.html
http://www.securitytracker.com/id?1019704
http://secunia.com/advisories/29526
http://secunia.com/advisories/29539
http://secunia.com/advisories/29541
http://secunia.com/advisories/29547
http://secunia.com/advisories/29558
http://secunia.com/advisories/29560
http://secunia.com/advisories/29616
http://secunia.com/advisories/29645
http://secunia.com/advisories/30327
http://secunia.com/advisories/30620
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1
SuSE Security Announcement: SUSE-SA:2008:019 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00002.html
http://www.ubuntu.com/usn/usn-592-1
http://www.vupen.com/english/advisories/2008/0998/references
http://www.vupen.com/english/advisories/2008/1793/references
Common Vulnerability Exposure (CVE) ID: CVE-2007-5338
1018836
http://securitytracker.com/id?1018836
20071026 rPSA-2007-0225-1 firefox
http://www.securityfocus.com/archive/1/482876/100/200/threaded
20071029 FLEA-2007-0062-1 firefox
http://www.securityfocus.com/archive/1/482925/100/0/threaded
20071029 rPSA-2007-0225-2 firefox thunderbird
http://www.securityfocus.com/archive/1/482932/100/200/threaded
26132
http://www.securityfocus.com/bid/26132
27276
http://secunia.com/advisories/27276
27298
http://secunia.com/advisories/27298
27311
http://secunia.com/advisories/27311
27315
http://secunia.com/advisories/27315
27325
http://secunia.com/advisories/27325
27327
http://secunia.com/advisories/27327
27335
http://secunia.com/advisories/27335
27336
http://secunia.com/advisories/27336
27356
http://secunia.com/advisories/27356
27360
http://secunia.com/advisories/27360
27383
http://secunia.com/advisories/27383
27387
http://secunia.com/advisories/27387
27403
http://secunia.com/advisories/27403
27414
http://secunia.com/advisories/27414
27425
http://secunia.com/advisories/27425
27480
http://secunia.com/advisories/27480
27665
http://secunia.com/advisories/27665
27680
http://secunia.com/advisories/27680
28398
http://secunia.com/advisories/28398
ADV-2007-3544
http://www.vupen.com/english/advisories/2007/3544
ADV-2007-3587
http://www.vupen.com/english/advisories/2007/3587
ADV-2008-0083
http://www.vupen.com/english/advisories/2008/0083
DSA-1392
http://www.debian.org/security/2007/dsa-1392
DSA-1396
http://www.debian.org/security/2007/dsa-1396
DSA-1401
http://www.debian.org/security/2007/dsa-1401
FEDORA-2007-2601
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00285.html
FEDORA-2007-2664
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00355.html
FEDORA-2007-3431
https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00498.html
GLSA-200711-14
http://www.gentoo.org/security/en/glsa/glsa-200711-14.xml
MDKSA-2007:202
http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:202
RHSA-2007:0979
http://www.redhat.com/support/errata/RHSA-2007-0979.html
RHSA-2007:0980
http://www.redhat.com/support/errata/RHSA-2007-0980.html
RHSA-2007:0981
http://www.redhat.com/support/errata/RHSA-2007-0981.html
USN-535-1
https://usn.ubuntu.com/535-1/
USN-536-1
http://www.ubuntu.com/usn/usn-536-1
http://support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.html
http://www.mozilla.org/security/announce/2007/mfsa2007-35.html
https://issues.rpath.com/browse/RPL-1858
mozilla-xpcnativewrapper-code-execution(37288)
https://exchange.xforce.ibmcloud.com/vulnerabilities/37288
oval:org.mitre.oval:def:10965
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10965
Common Vulnerability Exposure (CVE) ID: CVE-2007-6589
HPdes Security Advisory: HPSBUX02153
HPdes Security Advisory: SSRT061181
http://blog.beford.org/?p=8
http://osvdb.org/43477
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6033
Common Vulnerability Exposure (CVE) ID: CVE-2008-0420
BugTraq ID: 27826
http://www.securityfocus.com/bid/27826
Bugtraq: 20080216 [HISPASEC] FireFox 2.0.0.11 and Opera 9.50 beta Remote Memory Information Leak, FireFox 2.0.0.11 Remote Denial of Service (Google Search)
http://www.securityfocus.com/archive/1/488264/100/0/threaded
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html
http://www.mandriva.com/security/advisories?name=MDVSA-2008:048
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10119
http://securitytracker.com/id?1019434
http://secunia.com/advisories/28758
http://secunia.com/advisories/28839
http://secunia.com/advisories/29049
http://secunia.com/advisories/29098
http://secunia.com/advisories/29167
https://usn.ubuntu.com/576-1/
http://www.ubuntu.com/usn/usn-582-1
http://www.ubuntu.com/usn/usn-582-2
http://www.vupen.com/english/advisories/2008/0627/references
XForce ISS Database: firefox-bmp-dos(40606)
https://exchange.xforce.ibmcloud.com/vulnerabilities/40606
XForce ISS Database: firefox-bmp-information-disclosure(40491)
https://exchange.xforce.ibmcloud.com/vulnerabilities/40491
Common Vulnerability Exposure (CVE) ID: CVE-2008-1233
CERT/CC vulnerability note: VU#466521
http://www.kb.cert.org/vuls/id/466521
Debian Security Information: DSA-1574 (Google Search)
http://www.debian.org/security/2008/dsa-1574
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00058.html
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00074.html
http://www.mandriva.com/security/advisories?name=MDVSA-2008:155
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11078
http://www.redhat.com/support/errata/RHSA-2008-0207.html
RedHat Security Advisories: RHSA-2008:0208
http://rhn.redhat.com/errata/RHSA-2008-0208.html
http://www.redhat.com/support/errata/RHSA-2008-0209.html
http://www.securitytracker.com/id?1019694
http://secunia.com/advisories/29391
http://secunia.com/advisories/29548
http://secunia.com/advisories/29550
http://secunia.com/advisories/29607
http://secunia.com/advisories/30016
http://secunia.com/advisories/30094
http://secunia.com/advisories/30105
http://secunia.com/advisories/30192
http://secunia.com/advisories/30370
http://secunia.com/advisories/31043
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.447313
http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1
http://www.ubuntu.com/usn/usn-605-1
http://www.vupen.com/english/advisories/2008/0999/references
http://www.vupen.com/english/advisories/2008/2091/references
XForce ISS Database: mozilla-settimeout-code-execution(41443)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41443
Common Vulnerability Exposure (CVE) ID: CVE-2008-1234
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9551
XForce ISS Database: firefox-eventhandlers-xss(41455)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41455
Common Vulnerability Exposure (CVE) ID: CVE-2008-1235
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10980
XForce ISS Database: mozilla-principal-code-execution(41457)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41457
Common Vulnerability Exposure (CVE) ID: CVE-2008-1236
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11788
http://www.securitytracker.com/id?1019695
XForce ISS Database: mozilla-layoutengine-code-execution(41445)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41445
Common Vulnerability Exposure (CVE) ID: CVE-2008-1237
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9651
SuSE Security Announcement: SUSE-SR:2008:011 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.html
XForce ISS Database: firefox-javascript-engine-code-execution(41446)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41446
Common Vulnerability Exposure (CVE) ID: CVE-2008-1238
1019703
http://www.securitytracker.com/id?1019703
20080327 rPSA-2008-0128-1 firefox
238492
28448
29391
29526
29539
29541
29547
29550
29558
29560
29607
29616
29645
30327
30620
ADV-2008-0998
ADV-2008-1793
DSA-1532
DSA-1534
DSA-1535
GLSA-200805-18
MDVSA-2008:080
RHSA-2008:0207
RHSA-2008:0208
RHSA-2008:0209
SUSE-SA:2008:019
TA08-087A
USN-592-1
http://sla.ckers.org/forum/read.php?10%2C20033
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0128
http://www.mozilla.org/security/announce/2008/mfsa2008-16.html
mozilla-http-referrer-spoofing(41449)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41449
oval:org.mitre.oval:def:9889
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9889
Common Vulnerability Exposure (CVE) ID: CVE-2008-1240
XForce ISS Database: mozilla-liveconnect-unauthorized-access(41458)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41458
Common Vulnerability Exposure (CVE) ID: CVE-2008-1241
1019700
http://www.securitytracker.com/id?1019700
firefox-xul-popup-spoofing(41454)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41454
http://www.mozilla.org/security/announce/2008/mfsa2008-19.html
oval:org.mitre.oval:def:11163
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11163
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.