CVE-2013-5603
published 2013-10-30CVE-2013-5603: Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1…
PriorityP337critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.42%
91.9th percentile
Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving HTML document templates.
Affected
64 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 24.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 2.22 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-82rc-4rrx-5cj2: Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla Firefox before 25
ghsa_unreviewed·2022-05-14
CVE-2013-5603 [HIGH] GHSA-82rc-4rrx-5cj2: Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla Firefox before 25
Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving HTML document templates.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2013-10-31·CVSS 5.0
CVE-2013-1739 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple memory safety issues were discovered in Thunderbird. If a user
were tricked in to opening a specially crafted message with scripting
enabled, an attacker could possibly exploit these to cause a denial of
service via application crash, or potentially execute arbitrary code with
the privileges of the user invoking Thunderbird. (CVE-2013-1739,
CVE-2013-5590, CVE-2013-5591)
Jordi Chancel discovered that HTML select elements could display arbitrary
content. If a user had scripting enabled, an attacker could potentially
exploit this to conduct URL spoofing or clickjacking attacks.
(CVE-2013-5593)
Abhishek Arya discovered a crash when processing XSLT data in some
circumstances. If a user ha
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-10-29·CVSS 5.0
CVE-2013-1739 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple memory safety issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute arbitrary code with the privileges of the user
invoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,
CVE-2013-5592)
Jordi Chancel discovered that HTML select elements could display arbitrary
content. An attacker could potentially exploit this to conduct
URL spoofing or clickjacking attacks (CVE-2013-5593)
Abhishek Arya discovered a crash when processing XSLT data in some
circumstances. An attacker could potenti
Red Hat
Mozilla: Use-after-free in HTML document templates (MFSA 2013-102)
vendor_redhat·2013-10-29·CVSS 10.0
CVE-2013-5603 [CRITICAL] CWE-416 Mozilla: Use-after-free in HTML document templates (MFSA 2013-102)
Mozilla: Use-after-free in HTML document templates (MFSA 2013-102)
Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving HTML document templates.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - No
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-5603 Mozilla: Use-after-free in HTML document templates (MFSA 2013-102)
bugzilla·2013-10-28·CVSS 10.0
CVE-2013-5603 [CRITICAL] CVE-2013-5603 Mozilla: Use-after-free in HTML document templates (MFSA 2013-102)
CVE-2013-5603 Mozilla: Use-after-free in HTML document templates (MFSA 2013-102)
Security researcher Abhishek Arya (Inferno) of the Google Chrome Security Team used the Address Sanitizer tool to discover a user-after-free when interacting with HTML document templates. This leads to a potentially exploitable crash.
In general this flaw cannot be exploited through email in the Thunderbird and Seamonkey products because scripting is disabled, but is potentially a risk in browser or browser-like contexts.
External Reference:
http://www.mozilla.org/security/announce/2013/mfsa2013-102.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Abhishek Arya as the original reporter.
Statement:
This issue does not affect the ver
Bugzilla
CVE-2012-5603 CloudForms Katello: lack of authorization in proxies_controller.rb
bugzilla·2012-11-30·CVSS 5.5
CVE-2012-5603 [MEDIUM] CVE-2012-5603 CloudForms Katello: lack of authorization in proxies_controller.rb
CVE-2012-5603 CloudForms Katello: lack of authorization in proxies_controller.rb
Lukas Zapletal of Red Hat reports:
Regular user (somebody with username and password) and a consumer UUID of any
system can download the consumer certificate and consume content or modify
data without permission to do that.
Discussion:
Acknowledgements:
This issue was discovered by Lukas Zapletal of Red Hat.
---
This issue has been addressed in following products:
CloudForms for RHEL 6
CloudForms Tools for RHEL 5
Via RHSA-2012:1543 https://rhn.redhat.com/errata/RHSA-2012-1543.html
---
This issue has been addressed in following products:
Red Hat Subscription Asset Manager 1.2
Via RHSA-2013:0544 https://rhn.redhat.com/errata/RHSA-2013-0544.html
---
The Red Hat Security Response Team has rated this
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00006.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-102.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=916404https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19302https://security.gentoo.org/glsa/201504-01http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00006.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-102.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=916404https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19302https://security.gentoo.org/glsa/201504-01
2013-10-30
Published