Brief Hands-On Report--Mozilla released SeaMonkey 1.1.4
Mozilla release SeaMonkey 1.1.4, Mozilla's integrated Web suite. It is available for download from this Mozilla Web page.
According to Mozilla, v1.1.4 of SeaMonkey provided these security fixes over v1.1.3:
- MFSA 2007-27 Unescaped URIs passed to external programs
- MFSA 2007-26 Privilege escalation through chrome-loaded about:blank windows
- MFSA 2007-23 Remote code execution by launching SeaMonkey from Internet Explorer
The rough changelog provides these changes over v1.1.3, including the security fixes:
- 388121 about:blank loaded by chrome in particular ways has chrome privileges
- 389106 we may not escape quotes everywhere
- 389580 some schemes with %00 launch unexpected handlers on windows
- 389257 Cross-application scripting vulnerability in SeaMonkey
One of Macs only!'s staff uses SeaMonkey as their primary Web browser and email client so v1.1.4 received extensive use over the weekend. No issues were encountered. [Dana Baggett & Bill Fox]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?