CVE-2013-1690
published 2013-06-26CVE-2013-1690: Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle…
PriorityP183high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-04-18
Exploited in the wild
EPSS
69.02%
99.3th percentile
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| mozilla | firefox | < 22.0 | 22.0 |
| mozilla | firefox | >= 17.0 < 17.0.7 | 17.0.7 |
| mozilla | thunderbird | < 17.0.7 | 17.0.7 |
| mozilla | thunderbird_esr | >= 17.0 < 17.0.7 | 17.0.7 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | gluster_storage_server_for_on-premise | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
\x64\xa1\x18\x00\x00\x00
- →Exploit is triggered via a specially crafted web page using onreadystatechange events combined with the window.stop() API, causing a use-after-free of a DocumentViewerImpl object. Monitor browser traffic for pages combining these two mechanisms. ↗
- →Exploit was used in the wild in August 2013 targeting Tor Browser users. Inspect traffic from Tor Browser instances for exploitation attempts against Firefox 17.x. ↗
- ·The vulnerability cannot be exploited via email in Thunderbird or SeaMonkey because scripting is disabled in those contexts; exploitation risk is limited to browser or browser-like contexts. ↗
- ·The exploit sets EXITFUNC to 'process', meaning the payload terminates the entire Firefox process on exit rather than just the thread — post-exploitation forensics should account for process termination as a normal artifact. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_ubuntu10.0CRITICAL
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m5w3-m6g8-4mhf: Mozilla Firefox before 22
ghsa_unreviewed·2022-05-17
CVE-2013-1690 [HIGH] CWE-119 GHSA-m5w3-m6g8-4mhf: Mozilla Firefox before 22
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.
VulnCheck
Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability
vulncheck·2013·CVSS 8.8
CVE-2013-1690 [HIGH] CWE-119 Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability
Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability
Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.
Affected: Mozilla Firefox and Thunderbird
Required Action: Apply updates per vendor instructions.
Exploitation References: https://blogs.cisco.com/security/watering-hole-attacks-target-energy-sector; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/7f856b52404e
Remediation Due: 2022-04-18
CISA
Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability
cisa·2022-03-28·CVSS 8.8
CVE-2013-1690 [HIGH] CWE-119 Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability
Vulnerability: Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability
Affected: Mozilla Firefox and Thunderbird
Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-1690
Remediation Due Date: 2022-04-18
Ubuntu
Firefox regression
vendor_ubuntu·2013-07-03·CVSS 10.0
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: USN-1890-1 introduced a regression in Firefox.
USN-1890-1 fixed vulnerabilities in Firefox. This update introduced a
regression which sometimes resulted in Firefox using the wrong network
proxy settings. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple memory safety issues were discovered in Firefox. If the user were
tricked into opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2013-1682, CVE-2013-1683)
Abhishek Arya discovered multiple use-after-free bugs. If the user were
tricked into opening a specially crafted page, an attac
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2013-06-26·CVSS 10.0
CVE-2013-1682 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple memory safety issues were discovered in Thunderbird. If the user
were tricked into opening a specially crafted message with scripting
enabled, an attacker could possibly exploit these to cause a denial of
service via application crash, or potentially execute arbitrary code with
the privileges of the user invoking Thunderbird. (CVE-2013-1682)
Abhishek Arya discovered multiple use-after-free bugs. If the user were
tricked into opening a specially crafted message with scripting enabled,
an attacker could possibly exploit these to execute arbitrary code with
the privileges of the user invoking Thunderbird. (CVE-2013-1684,
CVE-2013-1685, CVE-2013-1686)
Mariusz Mlynski discovered that user
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-06-26·CVSS 10.0
CVE-2013-1682 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple memory safety issues were discovered in Firefox. If the user were
tricked into opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2013-1682, CVE-2013-1683)
Abhishek Arya discovered multiple use-after-free bugs. If the user were
tricked into opening a specially crafted page, an attacker could possibly
exploit these to execute arbitrary code with the privileges of the user
invoking Firefox. (CVE-2013-1684, CVE-2013-1685, CVE-2013-1686)
Mariusz Mlynski discovered that user defined
Red Hat
Mozilla: Execution of unmapped memory through onreadystatechange event (MFSA 2013-53)
vendor_redhat·2013-06-25·CVSS 8.8
CVE-2013-1690 [HIGH] Mozilla: Execution of unmapped memory through onreadystatechange event (MFSA 2013-53)
Mozilla: Execution of unmapped memory through onreadystatechange event (MFSA 2013-53)
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.
Package: thunderbird (Red Hat Enterprise Linux 5) - Affected
Red Hat
mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
vendor_redhat·2012-04-17·CVSS 4.0
CVE-2012-1703 [MEDIUM] mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1690.
Statement: On Red Hat Enterprise Linux 5.10, new MySQL 5.5 packages are available which are not vulnerable to this issue. Future updates for MySQL 5.0 will no longer be made available (mysql-5.0.* and related packages); security advisories will be provided only for MySQL 5.5. Please refer to https://rhn.redhat.com/errata/RHEA-2013-1330.html for further information.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
No detection rules found.
Exploit-DB
Mozilla Firefox - onreadystatechange Event DocumentViewerImpl Use-After-Free (Metasploit)
exploitdb·2013-08-08
CVE-2013-1690 Mozilla Firefox - onreadystatechange Event DocumentViewerImpl Use-After-Free (Metasploit)
Mozilla Firefox - onreadystatechange Event DocumentViewerImpl Use-After-Free (Metasploit)
---
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Firefox onreadystatechange Event DocumentViewerImpl Use After Free',
'Description' => %q{
This module exploits a vulnerability found on Firefox 17.0.6, specifically an use
after free of a DocumentViewerImpl object, triggered via an specially crafted web
page using onreadystatechange events and the window.stop() API, as exploited in the
wild on 2013 August to target Tor Browser users.
},
'License' => MSF_
Metasploit
Firefox onreadystatechange Event DocumentViewerImpl Use After Free
metasploit
Firefox onreadystatechange Event DocumentViewerImpl Use After Free
Firefox onreadystatechange Event DocumentViewerImpl Use After Free
This module exploits a vulnerability found on Firefox 17.0.6, specifically a use after free of a DocumentViewerImpl object, triggered via a specially crafted web page using onreadystatechange events and the window.stop() API, as exploited in the wild on 2013 August to target Tor Browser users.
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0981.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0982.htmlhttp://www.debian.org/security/2013/dsa-2716http://www.debian.org/security/2013/dsa-2720http://www.mozilla.org/security/announce/2013/mfsa2013-53.htmlhttp://www.securityfocus.com/bid/60778http://www.ubuntu.com/usn/USN-1890-1http://www.ubuntu.com/usn/USN-1891-1https://bugzilla.mozilla.org/show_bug.cgi?id=857883https://bugzilla.mozilla.org/show_bug.cgi?id=901365https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0981.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0982.htmlhttp://www.debian.org/security/2013/dsa-2716http://www.debian.org/security/2013/dsa-2720http://www.mozilla.org/security/announce/2013/mfsa2013-53.htmlhttp://www.securityfocus.com/bid/60778http://www.ubuntu.com/usn/USN-1890-1http://www.ubuntu.com/usn/USN-1891-1https://bugzilla.mozilla.org/show_bug.cgi?id=857883https://bugzilla.mozilla.org/show_bug.cgi?id=901365https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-1690
2013-06-26
Published
2022-03-28
Added to CISA KEV
Exploited in the wild