CVE-2013-1679
published 2013-05-16CVE-2013-1679: Use-after-free vulnerability in the mozilla::plugins::child::_geturlnotify function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird…
PriorityP337critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.44%
91.8th percentile
Use-after-free vulnerability in the mozilla::plugins::child::_geturlnotify function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 20.0.1 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | thunderbird | <= 17.0.5 | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird_esr | — | — |
| mozilla | thunderbird_esr | — | — |
| mozilla | thunderbird_esr | — | — |
| mozilla | thunderbird_esr | — | — |
| mozilla | thunderbird_esr | — | — |
| mozilla | thunderbird_esr | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-05-14·CVSS 10.0
CVE-2013-0801 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple memory safety issues were discovered in Firefox. If the user were
tricked into opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking Firefox.
(CVE-2013-0801, CVE-2013-1669)
Cody Crews discovered that some constructors could be used to bypass
restrictions enforced by their Chrome Object Wrapper (COW). An attacker
could exploit this to conduct cross-site scripting (XSS) attacks.
(CVE-2013-1670)
It was discovered that the file input element could expose the full local
path under certain conditions. An attack
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2013-05-14·CVSS 10.0
CVE-2013-0801 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple memory safety issues were discovered in Thunderbird. If the user
were tricked into opening a specially crafted message with scripting
enabled, an attacker could possibly exploit these to cause a denial of
service via application crash, or potentially execute code with the
privileges of the user invoking Thunderbird. (CVE-2013-0801,
CVE-2013-1669)
Cody Crews discovered that some constructors could be used to bypass
restrictions enforced by their Chrome Object Wrapper (COW). If a user had
scripting enabled, an attacker could exploit this to conduct cross-site
scripting (XSS) attacks. (CVE-2013-1670)
A use-after-free was discovered when resizing video content whilst it is
playing. If a
Red Hat
Mozilla: Memory corruption found using Address Sanitizer (MFSA 2013-48)
vendor_redhat·2013-05-14·CVSS 10.0
CVE-2013-1679 [CRITICAL] Mozilla: Memory corruption found using Address Sanitizer (MFSA 2013-48)
Mozilla: Memory corruption found using Address Sanitizer (MFSA 2013-48)
Use-after-free vulnerability in the mozilla::plugins::child::_geturlnotify function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
Package: thunderbird (Red Hat Enterprise Linux 5) - Affected
GHSA
GHSA-m7q9-pmrc-hx6r: Use-after-free vulnerability in the mozilla::plugins::child::_geturlnotify function in Mozilla Firefox before 21
ghsa_unreviewed·2022-05-17
CVE-2013-1679 [HIGH] GHSA-m7q9-pmrc-hx6r: Use-after-free vulnerability in the mozilla::plugins::child::_geturlnotify function in Mozilla Firefox before 21
Use-after-free vulnerability in the mozilla::plugins::child::_geturlnotify function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4518 RHUI: PKI entitlement certificates are world readable
bugzilla·2013-11-05·CVSS 5.5
CVE-2013-4518 [MEDIUM] CVE-2013-4518 RHUI: PKI entitlement certificates are world readable
CVE-2013-4518 RHUI: PKI entitlement certificates are world readable
Ina Panova of Red Hat reports:
Entitlement certificates keys have open permission in all client configuration rpms.
Custom client conf package:
[root@cli1 ~]# ls -la /etc/pki/entitlement/*key*
-rw-r--r--. 1 root root 1679 Nov 5 08:35 /etc/pki/entitlement/key.pem
[root@cli1 ~]#
Rh-amazon-rhui-client package:
[root@rhua ~]# ls -la /etc/pki/entitlement/*key*
-rw-r--r--. 1 root root 1675 Jan 22 2013 /etc/pki/entitlement/content-rhel6.key
-rw-r--r--. 1 root root 1679 Jan 22 2013 /etc/pki/entitlement/rhui-client-config-server-6.key
[root@rhua ~]#
Discussion:
OpenShift Online does not appear to be affected:
[appname-username.rhcloud.com 012345678901234567890123]\> cat /etc/pki/entitlement/content-rhel6.key
cat: /etc/pki
Bugzilla
CVE-2013-1676 CVE-2013-1677 CVE-2013-1678 CVE-2013-1679 CVE-2013-1680 CVE-2013-1681 Mozilla: Memory corruption found using Address Sanitizer (MFSA 2013-48)
bugzilla·2013-05-14·CVSS 10.0
CVE-2013-1676 [CRITICAL] CVE-2013-1676 CVE-2013-1677 CVE-2013-1678 CVE-2013-1679 CVE-2013-1680 CVE-2013-1681 Mozilla: Memory corruption found using Address Sanitizer (MFSA 2013-48)
CVE-2013-1676 CVE-2013-1677 CVE-2013-1678 CVE-2013-1679 CVE-2013-1680 CVE-2013-1681 Mozilla: Memory corruption found using Address Sanitizer (MFSA 2013-48)
Security researcher Abhishek Arya (Inferno) of the Google Chrome Security Team used the Address Sanitizer tool to discover a series of use-after-free, out of bounds read, and invalid write problems rated as moderate to critical as security issues in shipped software. Some of these issues are potentially exploitable, allowing for remote code execution. We would also like to thank Abhishek for reporting additional use-after-free flaws in dir=auto code introduced during Firefox development. These were fixed before general release.
External Reference:
http://www.mozilla.org/security/announce/2013/mfsa2013-48.html
Acknowledgements:
Re
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0820.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0821.htmlhttp://www.debian.org/security/2013/dsa-2699http://www.mandriva.com/security/advisories?name=MDVSA-2013:165http://www.mozilla.org/security/announce/2013/mfsa2013-48.htmlhttp://www.securityfocus.com/bid/59860http://www.ubuntu.com/usn/USN-1822-1http://www.ubuntu.com/usn/USN-1823-1https://bugzilla.mozilla.org/show_bug.cgi?id=848237https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17085http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0820.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0821.htmlhttp://www.debian.org/security/2013/dsa-2699http://www.mandriva.com/security/advisories?name=MDVSA-2013:165http://www.mozilla.org/security/announce/2013/mfsa2013-48.htmlhttp://www.securityfocus.com/bid/59860http://www.ubuntu.com/usn/USN-1822-1http://www.ubuntu.com/usn/USN-1823-1https://bugzilla.mozilla.org/show_bug.cgi?id=848237https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17085
2013-05-16
Published