CVE-2013-0765
published 2013-02-19CVE-2013-0765: Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 do not prevent multiple wrapping of WebIDL objects, which allows remote…
PriorityP341critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.74%
84.5th percentile
Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 do not prevent multiple wrapping of WebIDL objects, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| mozilla | firefox | < 19.0 | 19.0 |
| mozilla | seamonkey | < 2.16 | 2.16 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox regression
vendor_ubuntu·2013-03-01·CVSS 9.3
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: Due to a regression, Firefox might crash or freeze under normal use.
USN-1729-1 fixed vulnerabilities in Firefox. This update introduced a
regression which sometimes resulted in freezes and crashes when using
multiple tabs with images displayed. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Olli Pettay, Christoph Diehl, Gary Kwong, Jesse Ruderman, Andrew McCreight,
Joe Drew, Wayne Mery, Alon Zakai, Christian Holler, Gary Kwong, Luke
Wagner, Terrence Cole, Timothy Nikkel, Bill McCloskey, and Nicolas Pierron
discovered multiple memory safety issues affecting Firefox. If the user
were tricked into opening a specially crafted page, an attacker could
possibly exploit these to cause a denial of service via ap
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-02-20·CVSS 9.3
CVE-2013-0765 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it opened a
malicious website.
Olli Pettay, Christoph Diehl, Gary Kwong, Jesse Ruderman, Andrew McCreight,
Joe Drew, Wayne Mery, Alon Zakai, Christian Holler, Gary Kwong, Luke
Wagner, Terrence Cole, Timothy Nikkel, Bill McCloskey, and Nicolas Pierron
discovered multiple memory safety issues affecting Firefox. If the user
were tricked into opening a specially crafted page, an attacker could
possibly exploit these to cause a denial of service via application crash.
(CVE-2013-0783, CVE-2013-0784)
Atte Kettunen discovered that Firefox could perform an out-of-bounds read
while rendering GIF format images. An attacker could exploit this to crash
Firefox. (CVE-2013-0772)
Boris Zbarsky disco
Red Hat
Mozilla: Wrapped WebIDL objects can be wrapped again (MFSA 2013-23)
vendor_redhat·2013-02-19·CVSS 9.3
CVE-2013-0765 [CRITICAL] Mozilla: Wrapped WebIDL objects can be wrapped again (MFSA 2013-23)
Mozilla: Wrapped WebIDL objects can be wrapped again (MFSA 2013-23)
Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 do not prevent multiple wrapping of WebIDL objects, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-gv73-63gr-q7mh: Mozilla Firefox before 19
ghsa_unreviewed·2022-05-13
CVE-2013-0765 [HIGH] GHSA-gv73-63gr-q7mh: Mozilla Firefox before 19
Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 do not prevent multiple wrapping of WebIDL objects, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
Project0
Attacking ECMAScript Engines with Redefinition - Project Zero
project_zero·2015-08-01·CVSS 9.3
CVE-2013-0765 [CRITICAL] Attacking ECMAScript Engines with Redefinition - Project Zero
Posted by Natalie Silvanovich = function () { return n; }
ECMAScript has a property where almost all functions and variables can be dynamically redefined. This can lead to vulnerabilities in situations where native code assumes a function or variable behaves a certain way when accessed or does not have certain side effects when it can in fact be redefined. Project Zero has discovered 24 vulnerabilities involving ECMAScript redefinition in Adobe Flash in the past few months and similar issues have also been discovered in the wild. This post describes how this class of bugs works, alongside some examples of interesting bugs that have been recently patched.
ECMAScript Redefinition
Being a dynamically typed language, ECMAScript allows all functions to be redefined. For example, the JavaSc
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.htmlhttp://lists.opensuse.org/opensuse-updates/2013-02/msg00062.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-23.htmlhttp://www.ubuntu.com/usn/USN-1729-1http://www.ubuntu.com/usn/USN-1729-2https://bugzilla.mozilla.org/show_bug.cgi?id=830614https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17097http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.htmlhttp://lists.opensuse.org/opensuse-updates/2013-02/msg00062.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-23.htmlhttp://www.ubuntu.com/usn/USN-1729-1http://www.ubuntu.com/usn/USN-1729-2https://bugzilla.mozilla.org/show_bug.cgi?id=830614https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17097
2013-02-19
Published