HIGH
Mozilla: Integer overflow in ANGLE library (MFSA 2013-78)
Published Sep 18, 2013
9.3
HIGHCVSS 2.0
EPSS 4.36%
Description
Integer overflow in the drawLineLoop function in the libGLESv2 library in Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox before 24.0 and SeaMonkey before 2.21, allows remote attackers to execute arbitrary code via a crafted web site.
Affected products
No data.
Configuration 1
OR
- ≤ 2.20
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.0.6
- 2.0.7
- 2.0.8
- 2.0.9
- 2.0.10
- 2.0.11
- 2.0.12
- 2.0.13
- 2.0.14
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.10
- 2.10
- 2.10
- 2.10
- 2.10.1
- 2.11
- 2.11
- 2.11
- 2.11
- 2.11
- 2.11
- 2.11
- 2.12
- 2.12
- 2.12
- 2.12
- 2.12
- 2.12
- 2.12
- 2.12.1
- 2.13
- 2.13
- 2.13
- 2.13
- 2.13
- 2.13
- 2.13
- 2.13.1
- 2.13.2
- 2.14
- 2.14
- 2.14
- 2.14
- 2.14
- 2.14
- 2.15
- 2.15
- 2.15
- 2.15
- 2.15
- 2.15
- 2.15
- 2.15.1
- 2.15.2
- 2.16
- 2.16
- 2.16
- 2.16
- 2.16
- 2.16
- 2.16.1
- 2.16.2
- 2.17
- 2.17
- 2.17
- 2.17
- 2.17
- 2.17.1
- 2.18
- 2.18
- 2.18
- 2.18
- 2.19
- 2.19
- 2.19
- 2.20
- 2.20
- 2.20
Configuration 2
OR
- ≤ 23.0.1
- 19.0
- 19.0.1
- 19.0.2
- 20.0
- 20.0.1
- 21.0
- 22.0
- 23.0
No data.
Red Hat Enterprise Linux 5
firefox
Not affected
Red Hat Enterprise Linux 5
thunderbird
Not affected
Red Hat Enterprise Linux 6
firefox
Not affected
Red Hat Enterprise Linux 6
thunderbird
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 5 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 6 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 6 | thunderbird | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6
Weaknesses (2)
References (16)
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115907.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116610.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/117526.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-updates/2013-09/msg00055.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-09/msg00057.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-09/msg00061.html vendor-advisoryx_refsource_SUSE
- http://www.mozilla.org/security/announce/2013/mfsa2013-78.html x_refsource_CONFIRMVendor Advisory
- http://www.ubuntu.com/usn/USN-1951-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-1952-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2013-1721 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=890277 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=1009213 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-1748 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-1721
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18993 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2013-1721
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Sep 18, 2013
Updated Aug 6, 2024
Reserved Feb 13, 2013
Link CVE-2013-1721
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2013-1748 Assigner mozilla
Published Sep 18, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2013-1748