LWN.net Logo

mozilla: multiple vulnerabilities

Package(s):firefox, seamonkey CVE #(s):CVE-2013-1702 CVE-2013-1704 CVE-2013-1705 CVE-2013-1708 CVE-2013-1711
Created:August 7, 2013 Updated:August 19, 2013
Description: From the CVE entries:

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. (CVE-2013-1702)

Use-after-free vulnerability in the nsINode::GetParentNode function in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via vectors involving a DOM modification at the time of a SetBody mutation event. (CVE-2013-1704)

Heap-based buffer underflow in the cryptojs_interpret_key_gen_type function in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Certificate Request Message Format (CRMF) request.(CVE-2013-1705)

Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (application crash) via a crafted WAV file that is not properly handled by the nsCString::CharAt function. (CVE-2013-1708)

The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging access to an unprivileged object. (CVE-2013-1711)

Alerts:
Ubuntu USN-1924-1 2013-08-06
Ubuntu USN-1924-2 2013-08-06
openSUSE openSUSE-SU-2013:1334-1 2013-08-14
SUSE SUSE-SU-2013:1325-1 2013-08-14
openSUSE openSUSE-SU-2013:1348-1 2013-08-16
Fedora FEDORA-2013-14562 2013-08-18
Fedora FEDORA-2013-14568 2013-08-18
SUSE SUSE-SU-2013:1325-2 2013-08-23
SUSE SUSE-SU-2013:1382-1 2013-08-27
openSUSE openSUSE-SU-2013:1496-1 2013-09-27
Gentoo 201309-23 2013-09-27
SUSE SUSE-SU-2013:1497-1 2013-09-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds