Brief Hands-On Report--Mozilla released SeaMonkey 1.1.4

Mozilla release SeaMonkey 1.1.4, Mozilla's integrated Web suite. It is available for download from this Mozilla Web page.

According to Mozilla, v1.1.4 of SeaMonkey provided these security fixes over v1.1.3:

  • MFSA 2007-27 Unescaped URIs passed to external programs
  • MFSA 2007-26 Privilege escalation through chrome-loaded about:blank windows
  • MFSA 2007-23 Remote code execution by launching SeaMonkey from Internet Explorer

The rough changelog provides these changes over v1.1.3, including the security fixes:

  • 388121 about:blank loaded by chrome in particular ways has chrome privileges
  • 389106 we may not escape quotes everywhere
  • 389580 some schemes with %00 launch unexpected handlers on windows
  • 389257 Cross-application scripting vulnerability in SeaMonkey

One of Macs only!'s staff uses SeaMonkey as their primary Web browser and email client so v1.1.4 received extensive use over the weekend. No issues were encountered. [Dana Baggett & Bill Fox]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Reviews · This month in the archive