LWN.net Logo

mozilla: multiple vulnerabilities

Package(s):firefox thunderbird CVE #(s):CVE-2013-0749 CVE-2013-0770 CVE-2013-0760 CVE-2013-0761 CVE-2013-0763 CVE-2013-0771 CVE-2012-5829 CVE-2013-0768 CVE-2013-0764 CVE-2013-0745 CVE-2013-0747 CVE-2013-0752 CVE-2013-0757 CVE-2013-0755 CVE-2013-0756 CVE-2013-0743
Created:January 9, 2013 Updated:February 18, 2013
Description: From the Ubuntu advisory:

Christoph Diehl, Christian Holler, Mats Palmgren, Chiaki Ishikawa, Bill Gianopoulos, Benoit Jacob, Gary Kwong, Robert O'Callahan, Jesse Ruderman, and Julian Seward discovered multiple memory safety issues affecting Firefox. If the user were tricked into opening a specially crafted page, an attacker could possibly exploit these to cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. (CVE-2013-0769, CVE-2013-0749, CVE-2013-0770)

Abhishek Arya discovered several user-after-free and buffer overflows in Firefox. An attacker could exploit these to cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. (CVE-2013-0760, CVE-2013-0761, CVE-2013-0762, CVE-2013-0763, CVE-2013-0766, CVE-2013-0767, CVE-2013-0771, CVE-2012-5829)

A stack buffer was discovered in Firefox. If the user were tricked into opening a specially crafted page, an attacker could possibly exploit this to cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. (CVE-2013-0768)

Jerry Baker discovered that Firefox did not always properly handle threading when performing downloads over SSL connections. An attacker could exploit this to cause a denial of service via application crash. (CVE-2013-0764)

Olli Pettay and Boris Zbarsky discovered flaws in the Javacript engine of Firefox. An attacker could cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. (CVE-2013-0745, CVE-2013-0746)

Jesse Ruderman discovered a flaw in the way Firefox handled plugins. If a user were tricked into opening a specially crafted page, a remote attacker could exploit this to bypass security protections to conduct clickjacking attacks. (CVE-2013-0747)

Sviatoslav Chagaev discovered that Firefox did not properly handle XBL files with multiple XML bindings with SVG content. An attacker could cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. (CVE-2013-0752)

Mariusz Mlynski discovered two flaws to gain access to privileged chrome functions. An attacker could possibly exploit this to execute code with the privileges of the user invoking Firefox. (CVE-2013-0757, CVE-2013-0758)

Several use-after-free issues were discovered in Firefox. If the user were tricked into opening a specially crafted page, an attacker could possibly exploit this to execute code with the privileges of the user invoking Firefox. (CVE-2013-0753, CVE-2013-0754, CVE-2013-0755, CVE-2013-0756)

Two intermediate CA certificates were mis-issued by the TURKTRUST certificate authority. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to view sensitive information. (CVE-2013-0743)

Alerts:
Ubuntu USN-1681-1 2013-01-08
Ubuntu USN-1681-2 2013-01-08
Mandriva MDVSA-2013:002 2013-01-09
Slackware SSA:2013-009-01 2013-01-10
Slackware SSA:2013-009-02 2013-01-10
Mageia MGASA-2013-0008 2013-01-14
Ubuntu USN-1687-1 2013-01-14
Ubuntu USN-1687-2 2013-01-14
Fedora FEDORA-2013-0589 2013-01-15
Fedora FEDORA-2013-0306 2013-01-15
Fedora FEDORA-2013-0891 2013-01-16
SUSE SUSE-SU-2013:0048-1 2013-01-18
SUSE SUSE-SU-2013:0049-1 2013-01-18
Fedora FEDORA-2013-0653 2013-01-18
Ubuntu USN-1681-3 2013-01-22
Fedora FEDORA-2013-0885 2013-01-23
Fedora FEDORA-2013-0885 2013-01-23
openSUSE openSUSE-SU-2013:0149-1 2013-01-23
openSUSE openSUSE-SU-2013:0131-1 2013-01-23
openSUSE openSUSE-SU-2013:0175-1 2013-01-23
Fedora FEDORA-2013-1442 2013-01-26
Mageia MGASA-2013-0020 2013-01-26
Fedora FEDORA-2013-0723 2013-02-01
Fedora FEDORA-2013-1382 2013-02-02
Fedora FEDORA-2013-1432 2013-02-02
Ubuntu USN-1681-4 2013-02-05
SUSE SUSE-SU-2013:0292-1 2013-02-13
Mageia MGASA-2013-0053 2013-02-16
SUSE SUSE-SU-2013:0306-1 2013-02-18
Mandriva MDVSA-2013:050 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds