Opened 14 months ago
Closed 14 months ago
#21935 closed enhancement (fixed)
seamonkey-2.53.21
| Reported by: | Douglas R. Reno | Owned by: | zeckma |
|---|---|---|---|
| Priority: | high | Milestone: | 12.4 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version
Marking as High as it will have the security fixes from recent Firefox and Thunderbird releases included. There were over 50 bugfixes in this release as well, and they've revamped their build system a bit as well.
Change History (5)
comment:1 by , 14 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 14 months ago
comment:3 by , 14 months ago
Changelog from https://www.seamonkey-project.org/releases/seamonkey2.53.21/, not including any CVE information. I will gather the security info pretty soon here.
SeaMonkey 2.53.21 contains (among other changes) the following changes relative to SeaMonkey 2.53.20:
- Unable to load JSON Bookmarks file, Open/Cancel do the same thing.
- Move replaceVars helper into menu-manager.js for cZ.
- Remove dumpObject helper from utils.js in cZ.
- Remove toOpenWindowByType helper from utils.js in cZ.
- Fix makeLogName helper to not encode twice in prefs.js in cZ.
- Remove use of escapeFileName helper and tidy up pref_mungeName helper in cZ.
- Add helper to file-utils.js for ensuring an nsIFile is returned in cZ.
- Remove unused http.js file from cZ.
- Remove unused IRC tests from static.js in cZ.
- Switch from deprecated escape/unescape in cZ.
- Tidy up use of prefBranch outside of pref-manager in cZ.
- Make use of pref fallbacks in pref-manager in cZ.
- Remove unused edit context menu from cZ.
- Use XPCOMUtils.generateQI in connection-xpcom in cZ.
- Merge menus.xul, popups.xul and scripts.xul into chatzilla.xul.
- Make use of toSOutputStream and toSInputStream helpers in DCC code in cZ.
- Stop hard-coding commandkey for reloadui in cZ.
- Use suite's FillInHTMLTooltip helper instead of having own version in cZ.
- Split custom-away from other away/back commands in cZ.
- Remove ChatZilla Homepage link from Help menu and about command in cZ.
- Re-arrange toolbar menus in cZ.
- Remove ChatZilla Homepage link from about and prefs dialogs in cZ.
- Use custom controller for userlist and tidy up some controller use in cZ.
- Make use of observes for show/hide elements in cZ.
- Don't dynamically create focus-input key element in cZ.
- Remove unused toolbar creation code in cZ.
- Remove unused updateMenus code from cZ.
- Clean up whitespaces in cZ package manifest.
- Remove unused uninstallKeys code from cZ.
- Use node.remove(), especially instead of node.parentNode.removeChild(node) in cZ.
- Remove cz_condition from cZ.
- Remove outputWindowURL pref from cZ.
- Remove unused JS tests in cZ.
- Use includes, startsWith and endsWith instead of indexOf and substr in cZ.
- Use {} and [] instead of new Object() and new Array() in cZ.
- Fixup function naming for lint in cZ.
- Fixup method naming for lint in cZ.
- Remove old Mozilla 1.0 code from updateAppMotif in cZ.
- Use throw Components.Exception in cZ.
- Migrate output-window from HTML to XHTML to make localisation more standard in cZ.
- Merge munger.js into mungers.js in cZ.
- Remove unused tagName from mungers.js in cZ.
- Flatten directory structure in cZ.
- Tidy up about dialog page in cZ.
- Add helper to commands.js for sending CTCP commands in cZ.
- Migrate to standard menus for menu toolbar in cZ.
- Install plugin dialog broken in cZ.
- cZ change nick menu not working.
- Away status isn't reflected correctly in all channels in cZ.
- Fix dark motif userlist in cZ.
- SeaMonkey Composer adds moz-do-not-send attribute for links and images.
- Use menu_Toolbars overlay for navigatorOverlay and console.
- Remove defunct 2.53 prerelease builds from debugQA extension.
- Handling of MOZ_LANGPACK_CONTRIBUTORS in defines.inc files should be less custom.
- Control + U shortcut for underlined text is not working.
- Context menu search (with default search engine) does not work in the content area of a message compose or SM-Composer window.
The following bugs were fixed in our branch of the Gecko source code only:
- on FreeBSD sqlite3 fails to link for missing math functions.
- Expand init.configure to use version_package.txt to set MOZ_PKG_VERSION.
- Change supported msvc Compilers for SeaMonkey 2.53.
SeaMonkey 2.53.21 contains (among other changes) the following major changes relative to SeaMonkey 2.49.5:
- The Bookmarks Manager has switched its name to Library, and now also includes the History list. When History is invoked, the Library will be shown with the History list selected. The extensive modifications were needed because of Mozilla Gecko platform API changes.
- Download Manager has been migrated to a new API. Although it looks pretty much the same as before, the search option is missing and some other minor details work differently. The previous downloads history is removed during the upgrade.
- The layout panel was added to the CSS Grid tools.
- TLS 1.3 is the default SSL version now.
- Support for all NPAPI plugins like Flash, Java and Silverlight has been removed. For displaying pdf files in the browser you can use pdf.js-seamonkey from Isaac Schemm.
- SeaMonkey now uses a new api for formatting regional data like time and date. Default is to use the application locale of the current SeaMonkey build. If you use a language pack or a different OS formatting this is usually not desired. You can change the formatting from the application locale to the regional settings locale (OS) in the preferences dialog under "Appearance".
SeaMonkey 2.53.21 uses the same backend as Firefox and contains the relevant Firefox 60.8 security fixes.
SeaMonkey 2.53.21 shares most parts of the mail and news code with Thunderbird. Please read the Thunderbird 60.8.0 release notes for specific security fixes in this release.
Additional important security fixes up to Current Firefox 115.23 and Thunderbird 115.23 ESR plus many enhancements have been backported. We will continue to enhance SeaMonkey security in subsequent 2.53.x beta and release versions as fast as we are able to.
SeaMonkey-specific changes:
- SeaMonkey now uses gtk3 on Linux. If you experience a problem because of this please file a bug. Please try another OS theme first. Some of them are buggy and cause problems with SeaMonkey, Thunderbird and Firefox.
comment:4 by , 14 months ago
Overall rating: CRITICAL (4 critical CVEs)
CVE fixes:
- CVE-2025-1009 (High): Use-after-free in XSLT
- CVE-2025-1010 (High): Use-after-free in Custom Highlight
- CVE-2025-1012 (Moderate): Use-after-free during concurrent delazification
- CVE-2025-1016 (High): Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and Thunderbird 128.7
- CVE-2024-43097 (Critical): Overflow when growing an SkRegion's RunArray
- CVE-2025-1930 (High): AudioIPC StreamData could trigger a use-after-free in the Browser process
- CVE-2025-1931 (High): Use-after-free in WebTransportChild
- CVE-2025-1933 (High): JIT corruption of WASM i32 return values on 64-bit CPUs
- CVE-2025-1937 (High): Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 115.21, Firefox ESR 128.8, and Thunderbird 128.8
- CVE-2025-2857 (Critical): Incorrect handle could lead to sandbox escapes
- CVE-2025-3028 (High): Use-after-free triggered by XSLTProcessor
- CVE-2025-2817 (High): Privilege escalation in Firefox Updater
- CVE-2025-4083 (High): Process isolation bypass using "javascript:" URI links in cross-origin frames
- CVE-2025-4084 (Moderate): Potential local code execution in "copy as cURL" command
- CVE-2025-4918 (Critical): Out-of-bounds access when resolving Promise objects
- CVE-2025-4919 (Critical): Out-of-bounds access when optimizing linear sums

Fixed at ce94f09c372091d87a0cfb6165c634bf8a85b53a in the book. Changelog and security info coming in a bit and an SA will be filed after that.