Opened 11 months ago

Closed 11 months ago

Last modified 8 months ago

#22325 closed enhancement (fixed)

seamonkey-2.53.22

Reported by: Bruce Dubbs Owned by: zeckma
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: critical Keywords:
Cc:

Description

New point version.

Change History (8)

comment:1 by zeckma, 11 months ago

Owner: changed from blfs-book to zeckma
Status: new → assigned

comment:2 by zeckma, 11 months ago

Changes

  • Add Turkish (tr) to SeaMonkey Release builds.
  • Simplify setting context for output window in cZ.
  • Remove unused onMessageViewMouseDown from cZ.
  • Inline getViewsContext into initViewsPopup in cZ.
  • Inline getFontContext into initFont functions in cZ.
  • Migrate to standard menus for context in cZ.
  • Move getTabContext and getUserlistContext into menus.js for cZ.
  • Merge file-utils.js into utils.js for cZ.
  • Deduplicate code for centering dialogs in cZ.
  • Tidy up install-plugin dialog for cZ.
  • Colour the security lock in cZ.
  • Display the viewName for each tab in the statusbar in cZ.
  • Move client header information to title and status bars in cZ.
  • Remove unused motifSettings code from cZ.
  • Add href link to view names in statusbar in cZ.
  • Move network connection status information into statusbar in cZ.
  • Move channel mode and user counts out of header in cZ.
  • Move user header information into statusbar in cZ.
  • Move DCC chat information from header to statusbar in cZ.
  • Fix advanceKeyboardFocus in cZ.
  • Provide context menu to copy view status href in cZ.
  • Error when double clicking empty space in userlist in cZ.
  • Remove unused Gecko 1.7.x alert rules in cZ.
  • Remove use of removeUsers in cZ.
  • Context menu for userlist doesn't toggle both ways for sort and show modes in cZ.
  • Move and tidy output and splash code from output-window.js to static.js in cZ.
  • Move changeCSS code from output-window.js to static.js in cZ.
  • Move scrollToElement function from output-window.js to static.js in cZ.
  • Provide modern theme for cZ.
  • Port |Bug 1456035 - Add native QueryInterface helper with fast path for XPCWrappedJS| to SeaMonkey.
  • Change Windows Line endings in SeaMonkey source.
  • Null check this.browser in context menu.
  • Null check designMode in context menu.
  • Replace in-tree consumer of non-standard Iterator() with Object.{values,entries} in DOMi.
  • Restart with add-ons disabled is broken in SeaMonkey 2.53.22b1.
  • Calendar Color Chooser Unresponsive After Calendar Creation.

As far as I can tell from the security information, checking the SM repositories, and how they keep up to date with a given major.minor of Firefox and Thunderbird, there isn't any security fixes with this release.

comment:3 by zeckma, 11 months ago

I was wrong about security information. There are fixes, I'll prepare the information soon.

comment:4 by zeckma, 11 months ago

Severity: normal → critical

Security fixes

Level: Critical

  • Low: 1
  • Moderate: 5
  • High: 11
  • Critical: 1

  • CVE-2025-5263 (Moderate): Error handling for script execution was incorrectly isolated from web content
  • CVE-2025-5264 (Moderate): Potential local code execution in “Copy as cURL” command
  • CVE-2025-5265 (Moderate): Potential local code execution in “Copy as cURL” command
  • CVE-2025-5283 (Critical): Double-free in libvpx encoder
  • CVE-2025-6424 (High): Use-after-free in FontFaceSet
  • CVE-2025-6425 (Moderate): The WebCompat WebExtension shipped with Firefox exposed a persistent UUID
  • CVE-2025-8027 (High): JavaScript engine only wrote partial return value to stack
  • CVE-2025-8028 (High): Large branch table could lead to truncated instruction
  • CVE-2025-8033 (Low): Incorrect JavaScript state machine for generators
  • CVE-2025-8034 (High): Memory safety bugs
  • CVE-2025-9179 (High): Sandbox escape due to invalid pointer in the Audio/Video: GMP component
  • CVE-2025-9180 (High): Same-origin policy bypass in the Graphics: Canvas2D component
  • CVE-2025-9185 (High): Memory safety bugs
  • CVE-2025-10533 (Moderate): Integer overflow in the SVG component
  • CVE-2025-11709 (High): Out of bounds read/write in a privileged process triggered by WebGL textures
  • CVE-2025-11710 (High): Cross-process information leaked due to malicious IPC messages
  • CVE-2025-11711 (High): Some non-writable Object properties could be modified
  • CVE-2025-11714 (High): Memory safety bugs.

comment:5 by zeckma, 11 months ago

Priority: normal → high

comment:6 by zeckma, 11 months ago

Fixed at 2973645cb6234dd489b79d660d859b151f441076. Keeping open for SA issuing.

comment:7 by zeckma, 11 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-030 issued.

comment:8 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.