Mozilla: Use-after-free with video and onresize event (MFSA 2013-46)
Published May 16, 2013
9.3
HIGHCVSS 2.0
EPSS 5.83%
Description
Use-after-free vulnerability in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code via vectors involving an onresize event during the playing of a video.
Affected products
No data.
Configuration 1
Configuration 2
Configuration 3
- ≤ 17.0.5
- 17.0
- 17.0.1
- 17.0.2
- 17.0.3
- 17.0.4
Configuration 4
- 17.0
- 17.0.1
- 17.0.2
- 17.0.3
- 17.0.4
- 17.0.5
No data.
Red Hat Enterprise Linux 5
firefox-0:17.0.6-1.el5_9
Fixed · RHSA-2013:0820
Red Hat Enterprise Linux 5
thunderbird-0:17.0.6-1.el5_9
Fixed · RHSA-2013:0821
Red Hat Enterprise Linux 5
xulrunner-0:17.0.6-1.el5_9
Fixed · RHSA-2013:0820
Red Hat Enterprise Linux 6
firefox-0:17.0.6-1.el6_4
Fixed · RHSA-2013:0820
Red Hat Enterprise Linux 6
thunderbird-0:17.0.6-2.el6_4
Fixed · RHSA-2013:0821
Red Hat Enterprise Linux 6
xulrunner-0:17.0.6-2.el6_4
Fixed · RHSA-2013:0820
Red Hat Enterprise Linux 5
thunderbird
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | firefox-0:17.0.6-1.el5_9 | Fixed | RHSA-2013:0820 |
| Red Hat Enterprise Linux 5 | thunderbird-0:17.0.6-1.el5_9 | Fixed | RHSA-2013:0821 |
| Red Hat Enterprise Linux 5 | xulrunner-0:17.0.6-1.el5_9 | Fixed | RHSA-2013:0820 |
| Red Hat Enterprise Linux 6 | firefox-0:17.0.6-1.el6_4 | Fixed | RHSA-2013:0820 |
| Red Hat Enterprise Linux 6 | thunderbird-0:17.0.6-2.el6_4 | Fixed | RHSA-2013:0821 |
| Red Hat Enterprise Linux 6 | xulrunner-0:17.0.6-2.el6_4 | Fixed | RHSA-2013:0820 |
| Red Hat Enterprise Linux 5 | thunderbird | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (19)
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2013-0820.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2013-0821.html vendor-advisoryx_refsource_REDHAT
- http://www.debian.org/security/2013/dsa-2699 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:165 vendor-advisoryx_refsource_MANDRIVA
- http://www.mozilla.org/security/announce/2013/mfsa2013-46.html x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/59859 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-1822-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-1823-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2013-1674 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=860971 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=962598 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-1674
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17147 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2013-1674
Change history (0)
No recorded changes yet.