Opened 8 months ago

Closed 7 months ago

#22826 closed enhancement (fixed)

Backport the fix for CVE-2026-2447 to seamonkey

Reported by: Douglas R. Reno Owned by: zeckma
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

Both Thunderbird and Firefox got emergency updates for a high severity heap buffer overflow problem in libvpx. We use the system copy for both of those packages, so we in theory shouldn't be affected by those unless a user didn't install the recommended dependencies (which is certainly possible and part of why we should be doing those anyway)

On the other hand, Seamonkey does use the bundled copy of libvpx, so it's directly impacted by this issue. It looks like a remote code execution rated as 8.8 High, and can be triggered via video playback. Note though that some sites use autoplay and a user can thus get hit by this vulnerability through normal browsing activities.

Change History (4)

comment:1 by Douglas R. Reno, 7 months ago

Owner: changed from blfs-book to zeckma

comment:2 by zeckma, 7 months ago

Status: new → assigned

comment:3 by zeckma, 7 months ago

Fixed at c8199480b8776e50e82ef738bbb8d94973df4e0a. Leaving open for SA.

comment:4 by zeckma, 7 months ago

Resolution: → fixed
Status: assigned → closed

Addressed in SA-12.4-100.

Note: See TracTickets for help on using tickets.