LWN.net Logo

Advertisement

f-irc: away with the old irc-client paradigms! The graphical-interface feeling in a terminal. Give it a try!

Advertise here

mozilla: multiple vulnerabilities

Package(s):firefox CVE #(s):CVE-2013-1683 CVE-2013-1688 CVE-2013-1695 CVE-2013-1696 CVE-2013-1698 CVE-2013-1699
Created:June 26, 2013 Updated:July 3, 2013
Description: From the CVE entries:

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 22.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. (CVE-2013-1683)

The Profiler implementation in Mozilla Firefox before 22.0 parses untrusted data during UI rendering, which allows user-assisted remote attackers to execute arbitrary JavaScript code via a crafted web site. (CVE-2013-1688)

Mozilla Firefox before 22.0 does not properly implement certain DocShell inheritance behavior for the sandbox attribute of an IFRAME element, which allows remote attackers to bypass intended access restrictions via a FRAME element within an IFRAME element. (CVE-2013-1695)

Mozilla Firefox before 22.0 does not properly enforce the X-Frame-Options protection mechanism, which allows remote attackers to conduct clickjacking attacks via a crafted web site that uses the HTTP server push feature with multipart responses. (CVE-2013-1696)

The getUserMedia permission implementation in Mozilla Firefox before 22.0 references the URL of a top-level document instead of the URL of a specific page, which makes it easier for remote attackers to trick users into permitting camera or microphone access via a crafted web site that uses IFRAME elements. (CVE-2013-1698)

The Internationalized Domain Name (IDN) display algorithm in Mozilla Firefox before 22.0 does not properly handle the .com, .name, and .net top-level domains, which allows remote attackers to spoof the address bar via unspecified homograph characters. (CVE-2013-1699)

Alerts:
Ubuntu USN-1890-1 2013-06-26
Fedora FEDORA-2013-11799 2013-06-28
Fedora FEDORA-2013-11776 2013-06-28
Fedora FEDORA-2013-11799 2013-06-28
Fedora FEDORA-2013-11776 2013-06-28
Ubuntu USN-1890-2 2013-07-03
openSUSE openSUSE-SU-2013:1142-1 2013-07-04
openSUSE openSUSE-SU-2013:1140-1 2013-07-04
openSUSE openSUSE-SU-2013:1180-1 2013-07-11
openSUSE openSUSE-SU-2013:1176-1 2013-07-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds