cbcvebase.
CVE-2013-1055
published 2021-04-07

CVE-2013-1055: The unity-firefox-extension package could be tricked into dropping a C callback which was still in use, which Firefox would then free, causing Firefox to…

PriorityP418medium4.3CVSS 3.1
AVNACLPRNUIRSUCNINAL
EPSS
1.27%
67.1th percentile
The unity-firefox-extension package could be tricked into dropping a C callback which was still in use, which Firefox would then free, causing Firefox to crash. This could be achieved by adding an action to the launcher and updating it with new callbacks until the libunity-webapps rate limit was hit. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 of unity-firefox-extension and in all versions of libunity-webapps by shipping an empty unity-firefox-extension package, thus disabling the extension entirely and invalidating the attack against the libunity-webapps package.

Affected

6 ranges
VendorProductVersion rangeFixed in
canonicallibunity-webapps>= 2.5.0 < 2.5.0~+14.04.20140409-0ubuntu12.5.0~+14.04.20140409-0ubuntu1
canonicalubuntu_linux
canonicalubuntu_linux
canonicalunity-firefox-extension< 3.0.0\+14.04.20140416-0ubuntu1.14.04.13.0.0\+14.04.20140416-0ubuntu1.14.04.1
canonicalunity-firefox-extension>= 0 < 3.0.0+14.04.20140416-0ubuntu1.14.04.13.0.0+14.04.20140416-0ubuntu1.14.04.1
canonicalunity-firefox-extension>= 3.0.0 < 3.0.0+14.04.20140416-0ubuntu1.14.04.13.0.0+14.04.20140416-0ubuntu1.14.04.1

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.