CVE-2013-1732
published 2013-09-18CVE-2013-1732: Buffer overflow in the nsFloatManager::GetFlowArea function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0…
PriorityP348critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
8.89%
94.6th percentile
Buffer overflow in the nsFloatManager::GetFlowArea function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code via crafted use of lists and floats within a multi-column layout.
Affected
74 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 23.0.1 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 2.20 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_ubuntu10.0CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2013-09-18·CVSS 10.0
CVE-2013-1718 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple memory safety issues were discovered in Thunderbird. If a user
were tricked in to opening a specially crafted message with scripting
enabled, an attacker could possibly exploit these to cause a denial of
service via application crash, or potentially execute arbitrary code with
the privileges of the user invoking Thunderbird. (CVE-2013-1718)
Atte Kettunen discovered a flaw in the HTML5 Tree Builder when interacting
with template elements. If a user had scripting enabled, in some
circumstances an attacker could potentially exploit this to execute
arbitrary code with the privileges of the user invoking Thunderbird.
(CVE-2013-1720)
Alex Chapman discovered an integer overflow vulnerabilit
Red Hat
Mozilla: Buffer overflow with multi-column, lists, and floats (MFSA 2013-89)
vendor_redhat·2013-09-17·CVSS 9.3
CVE-2013-1732 [CRITICAL] Mozilla: Buffer overflow with multi-column, lists, and floats (MFSA 2013-89)
Mozilla: Buffer overflow with multi-column, lists, and floats (MFSA 2013-89)
Buffer overflow in the nsFloatManager::GetFlowArea function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code via crafted use of lists and floats within a multi-column layout.
Package: thunderbird (Red Hat Enterprise Linux 5) - Affected
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-09-17·CVSS 10.0
CVE-2013-1718 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple memory safety issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute arbitrary code with the privileges of the user
invoking Firefox. (CVE-2013-1718, CVE-2013-1719)
Atte Kettunen discovered a flaw in the HTML5 Tree Builder when interacting
with template elements. In some circumstances, an attacker could
potentially exploit this to execute arbitrary code with the privileges of
the user invoking Firefox. (CVE-2013-1720)
Alex Chapman discovered an integer overflow vulnerability in the ANGLE
GHSA
GHSA-82v3-8qpg-x8r6: Buffer overflow in the nsFloatManager::GetFlowArea function in Mozilla Firefox before 24
ghsa_unreviewed·2022-05-17
CVE-2013-1732 [HIGH] CWE-119 GHSA-82v3-8qpg-x8r6: Buffer overflow in the nsFloatManager::GetFlowArea function in Mozilla Firefox before 24
Buffer overflow in the nsFloatManager::GetFlowArea function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code via crafted use of lists and floats within a multi-column layout.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1732 Mozilla: Buffer overflow with multi-column, lists, and floats (MFSA 2013-89)
bugzilla·2013-09-17·CVSS 9.3
CVE-2013-1732 [CRITICAL] CVE-2013-1732 Mozilla: Buffer overflow with multi-column, lists, and floats (MFSA 2013-89)
CVE-2013-1732 Mozilla: Buffer overflow with multi-column, lists, and floats (MFSA 2013-89)
Security researcher Aki Helin reported that combining lists, floats, and multiple columns could trigger a potentially exploitable buffer overflow.
In general this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled, but is potentially a risk in browser or browser-like contexts.
External Reference:
http://www.mozilla.org/security/announce/2013/mfsa2013-89.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Aki Helin as the original reporter.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2013:1269 htt
Bugzilla
CVE-2013-1813 busybox: insecure directory permissions in /dev
bugzilla·2013-03-08·CVSS 7.2
CVE-2013-1813 [HIGH] CVE-2013-1813 busybox: insecure directory permissions in /dev
CVE-2013-1813 busybox: insecure directory permissions in /dev
It was reported [1] that busybox creates part of the /dev directory tree with incorrect permissions when creating device nodes in nested directories. This has been fixed [2] upstream.
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=701965
[2] http://git.busybox.net/busybox/commit/?id=4609f477c7e043a4f6147dfe6e86b775da2ef784
Discussion:
Created busybox tracking bugs for this issue
Affects: fedora-all [bug 919610]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:1732 https://rhn.redhat.com/errata/RHSA-2013-1732.html
---
Statement:
(none)
http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115907.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-September/116610.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-September/117526.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00055.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00057.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00059.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00060.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00061.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1268.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1269.htmlhttp://www.debian.org/security/2013/dsa-2762http://www.mozilla.org/security/announce/2013/mfsa2013-89.htmlhttp://www.securityfocus.com/bid/62469http://www.ubuntu.com/usn/USN-1951-1http://www.ubuntu.com/usn/USN-1952-1https://bugzilla.mozilla.org/show_bug.cgi?id=883514https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18520http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115907.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-September/116610.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-September/117526.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00055.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00057.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00059.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00060.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00061.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1268.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1269.htmlhttp://www.debian.org/security/2013/dsa-2762http://www.mozilla.org/security/announce/2013/mfsa2013-89.htmlhttp://www.securityfocus.com/bid/62469http://www.ubuntu.com/usn/USN-1951-1http://www.ubuntu.com/usn/USN-1952-1https://bugzilla.mozilla.org/show_bug.cgi?id=883514https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18520
2013-09-18
Published