LWN.net Logo

Advertisement

f-irc: away with the old irc-client paradigms! The graphical-interface feeling in a terminal. Give it a try!

Advertise here

mozilla: multiple vulnerabilities

Package(s):firefox thunderbird seamonkey CVE #(s):CVE-2013-1682 CVE-2013-1684 CVE-2013-1685 CVE-2013-1686 CVE-2013-1687 CVE-2013-1690 CVE-2013-1692 CVE-2013-1693 CVE-2013-1694 CVE-2013-1697
Created:June 26, 2013 Updated:July 23, 2013
Description: From the CVE entries:

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. (CVE-2013-1682)

Use-after-free vulnerability in the mozilla::dom::HTMLMediaElement::LookupMediaElementURITable function in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted web site. (CVE-2013-1684)

Use-after-free vulnerability in the nsIDocument::GetRootElement function in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted web site. (CVE-2013-1685)

Use-after-free vulnerability in the mozilla::ResetDir function in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors. (CVE-2013-1686)

The System Only Wrapper (SOW) and Chrome Object Wrapper (COW) implementations in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly restrict XBL user-defined functions, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges, or conduct cross-site scripting (XSS) attacks, via a crafted web site. (CVE-2013-1687)

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location. (CVE-2013-1690)

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not prevent the inclusion of body data in an XMLHttpRequest HEAD request, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web site. (CVE-2013-1692)

The SVG filter implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to read pixel values, and possibly bypass the Same Origin Policy and read text from a different domain, by observing timing differences in execution of filter code. (CVE-2013-1693)

The PreserveWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly handle the lack of a wrapper, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by leveraging unintended clearing of the wrapper cache's preserved-wrapper flag. (CVE-2013-1694)

The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers use of a user-defined (1) toString or (2) valueOf method. (CVE-2013-1697)

Alerts:
Red Hat RHSA-2013:0981-01 2013-06-25
Red Hat RHSA-2013:0982-01 2013-06-25
Scientific Linux SL-fire-20130626 2013-06-26
Scientific Linux SL-thun-20130626 2013-06-26
CentOS CESA-2013:0981 2013-06-26
CentOS CESA-2013:0981 2013-06-26
CentOS CESA-2013:0982 2013-06-26
CentOS CESA-2013:0982 2013-06-26
CentOS CESA-2013:0981 2013-06-26
CentOS CESA-2013:0981 2013-06-26
Oracle ELSA-2013-0981 2013-06-25
Oracle ELSA-2013-0981 2013-06-26
Oracle ELSA-2013-0982 2013-06-25
Ubuntu USN-1890-1 2013-06-26
Debian DSA-2716-1 2013-06-26
Ubuntu USN-1891-1 2013-06-26
Mageia MGASA-2013-0189 2013-06-26
Mandriva MDVSA-2013:179 2013-06-26
Fedora FEDORA-2013-11799 2013-06-28
Fedora FEDORA-2013-11776 2013-06-28
Fedora FEDORA-2013-11799 2013-06-28
Fedora FEDORA-2013-11776 2013-06-28
Fedora FEDORA-2013-11799 2013-06-28
Fedora FEDORA-2013-11776 2013-06-28
Slackware SSA:2013-180-01 2013-06-29
Slackware SSA:2013-180-02 2013-06-29
Ubuntu USN-1890-2 2013-07-03
openSUSE openSUSE-SU-2013:1142-1 2013-07-04
openSUSE openSUSE-SU-2013:1141-1 2013-07-04
openSUSE openSUSE-SU-2013:1140-1 2013-07-04
openSUSE openSUSE-SU-2013:1143-1 2013-07-04
Debian DSA-2720-1 2013-07-06
SUSE SUSE-SU-2013:1152-1 2013-07-05
SUSE SUSE-SU-2013:1153-1 2013-07-05
openSUSE openSUSE-SU-2013:1180-1 2013-07-11
openSUSE openSUSE-SU-2013:1176-1 2013-07-11
Fedora FEDORA-2013-12711 2013-07-23
Fedora FEDORA-2013-12698 2013-07-23
Fedora FEDORA-2013-12745 2013-07-23
Gentoo 201309-23 2013-09-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds