Opened 8 months ago
Closed 7 months ago
#22826 closed enhancement (fixed)
Backport the fix for CVE-2026-2447 to seamonkey
| Reported by: | Douglas R. Reno | Owned by: | zeckma |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
Both Thunderbird and Firefox got emergency updates for a high severity heap buffer overflow problem in libvpx. We use the system copy for both of those packages, so we in theory shouldn't be affected by those unless a user didn't install the recommended dependencies (which is certainly possible and part of why we should be doing those anyway)
On the other hand, Seamonkey does use the bundled copy of libvpx, so it's directly impacted by this issue. It looks like a remote code execution rated as 8.8 High, and can be triggered via video playback. Note though that some sites use autoplay and a user can thus get hit by this vulnerability through normal browsing activities.
Change History (4)
comment:1 by , 7 months ago
| Owner: | changed from to |
|---|
comment:2 by , 7 months ago
| Status: | new → assigned |
|---|

Fixed at c8199480b8776e50e82ef738bbb8d94973df4e0a. Leaving open for SA.