LWN.net Logo

mozilla: multiple vulnerabilities

Package(s):Mozilla CVE #(s):CVE-2013-0789 CVE-2013-0791 CVE-2013-0792 CVE-2013-0794
Created:April 5, 2013 Updated:April 5, 2013
Description:

From the Mozilla Security Center page for Firefox 20:

Andrew McCreight, Randell Jesup, Gary Kwong, Jesse Ruderman, Christian Holler, and Mats Palmgren reported memory safety problems and crashes that affect Firefox 19. (CVE-2013-0789)

Mozilla community member Ambroz Bizjak reported an out-of-bounds array read in the CERT_DecodeCertPackage function of the Network Security Services (NSS) libary when decoding a certificate. When this occurs, it will lead to memory corruption and a non-exploitable crash. (CVE-2013-0791)

Mozilla community member Tobias Schula reported that if gfx.color_management.enablev4 preference is enabled manually in about:config, some grayscale PNG images will be rendered incorrectly and cause memory corruption during PNG decoding when certain color profiles are in use. A crafted PNG image could use this flaw to leak data through rendered images drawing from random memory. By default, this preference is not enabled. (CVE-2013-0792)

Security researcher shutdown reported a method for removing the origin indication on tab-modal dialog boxes in combination with browser navigation. This could allow an attacker's dialog to overlay a page and show another site's content. This can be used for phishing by allowing users to enter data into a modal prompt dialog on an attacking, site while appearing to be from the displayed site. (CVE-2013-0794)

Alerts:
openSUSE openSUSE-SU-2013:0630-1 2013-04-05
Fedora FEDORA-2013-4832 2013-04-05
Fedora FEDORA-2013-4832 2013-04-05
Ubuntu USN-1786-1 2013-04-04
Ubuntu USN-1786-2 2013-04-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds