Mozilla: Use-after-free in synthetic mouse movement (MFSA 2013-114)
Published Dec 11, 2013
9.8
CRITICALCVSS 3.1
EPSS 9.45%
Description
Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving synthetic mouse movement, related to the RestyleManager::GetHoverGeneration function.
Affected products
No data.
Configuration 1
Configuration 2
- 18
- 19
- 20
Configuration 3
- 11.0
- 12.2
- 12.3
- 13.1
- 11
- 11
- 11
Configuration 4
- 5.0
- 6.0
- 6.5
- 5.0
- 6.0
- 6.5
- 6.5
- 6.5
- 5.0
- 6.0
Configuration 5
- 12.04
- 12.10
- 13.04
- 13.10
No data.
Red Hat Enterprise Linux 5
firefox-0:24.2.0-1.el5_10
Fixed · RHSA-2013:1812
Red Hat Enterprise Linux 5
thunderbird-0:24.2.0-2.el5_10
Fixed · RHSA-2013:1823
Red Hat Enterprise Linux 6
firefox-0:24.2.0-1.el6_5
Fixed · RHSA-2013:1812
Red Hat Enterprise Linux 6
thunderbird-0:24.2.0-1.el6_5
Fixed · RHSA-2013:1823
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | firefox-0:24.2.0-1.el5_10 | Fixed | RHSA-2013:1812 |
| Red Hat Enterprise Linux 5 | thunderbird-0:24.2.0-2.el5_10 | Fixed | RHSA-2013:1823 |
| Red Hat Enterprise Linux 6 | firefox-0:24.2.0-1.el6_5 | Fixed | RHSA-2013:1812 |
| Red Hat Enterprise Linux 6 | thunderbird-0:24.2.0-1.el6_5 | Fixed | RHSA-2013:1823 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (27)
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/123437.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124108.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124257.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-January/125470.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00085.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00086.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00087.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00119.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00120.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00121.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00002.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1812.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.mozilla.org/security/announce/2013/mfsa2013-114.html x_refsource_CONFIRMVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html x_refsource_CONFIRMThird Party Advisory
- http://www.securitytracker.com/id/1029470 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1029476 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2052-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2053-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2013-5613 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=930381 x_refsource_CONFIRMExploitIssue TrackingVendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=932449 x_refsource_CONFIRMExploitIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1039429 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-5453 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-5613
- https://security.gentoo.org/glsa/201504-01 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2013-5613
Change history (0)
No recorded changes yet.