"The vulnerability has been labelled CVE-2023-4863"

Discussion of bugs in Seamonkey
Post Reply
v_v
Posts: 144
Joined: September 18th, 2021, 8:57 am

"The vulnerability has been labelled CVE-2023-4863"

Post by v_v »

[I am not sure where to post this so by default I have posted it in "SeaMonkey Bugs".]


Do we need to be concerned about this new vulnerability "CVE-2023-4863"? See " https://www.pcworld.com/article/2068973 ... owser.html ". It appears that many or most other browsers have issued emergency patches.

v_v
User avatar
ElTxolo
Posts: 2754
Joined: July 30th, 2007, 9:35 am
Location: Localhost

Re: "The vulnerability has been labelled CVE-2023-4863"

Post by ElTxolo »

v_v wrote:
September 16th, 2023, 6:19 am
[....] Do we need to be concerned about this new vulnerability "CVE-2023-4863"?
Know issue. #-o


See: #seamonkey - seamonkey/20230913#c217567






Cheers !! Image
How to Ask Questions The Smart Way - How to Report Bugs Effectively ;)
Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20230917 SeaMonkey/2.53.17.1
Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 SeaMonkey/2.53.18
frg
Posts: 1339
Joined: December 15th, 2015, 1:20 pm

Re: "The vulnerability has been labelled CVE-2023-4863"

Post by frg »

The 2.53.17.1 new release is tracked in https://bugzilla.mozilla.org/show_bug.cgi?id=1853565 and should appear soonish. 2.53.18b1 pre is fixed since last week.

Sorry for the delay but 2.53.17.1 needed a few more backports which were already in 2.53.18b1 pre.
User avatar
ElTxolo
Posts: 2754
Joined: July 30th, 2007, 9:35 am
Location: Localhost

Re: "The vulnerability has been labelled CVE-2023-4863"

Post by ElTxolo »

Image For those who want to download the update to SeaMonkey 2.53.17.1 is available NOW:

How to Ask Questions The Smart Way - How to Report Bugs Effectively ;)
Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20230917 SeaMonkey/2.53.17.1
Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 SeaMonkey/2.53.18
frg
Posts: 1339
Joined: December 15th, 2015, 1:20 pm

Re: "The vulnerability has been labelled CVE-2023-4863"

Post by frg »

Website has now been updated (might need a release). If updates are not yet enable ewong will do later I am sure:
https://www.seamonkey-project.org/relea ... 2.53.17.1/

A second libwep fix for the upcoming Firefox esr115.3 is also already included.
Post Reply