CVE-2013-5604
published 2013-10-30CVE-2013-5604: The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1…
PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.49%
93.0th percentile
The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly initialize data, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via crafted documents.
Affected
83 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 24.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 2.22 | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2013-10-31·CVSS 5.0
CVE-2013-1739 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple memory safety issues were discovered in Thunderbird. If a user
were tricked in to opening a specially crafted message with scripting
enabled, an attacker could possibly exploit these to cause a denial of
service via application crash, or potentially execute arbitrary code with
the privileges of the user invoking Thunderbird. (CVE-2013-1739,
CVE-2013-5590, CVE-2013-5591)
Jordi Chancel discovered that HTML select elements could display arbitrary
content. If a user had scripting enabled, an attacker could potentially
exploit this to conduct URL spoofing or clickjacking attacks.
(CVE-2013-5593)
Abhishek Arya discovered a crash when processing XSLT data in some
circumstances. If a user ha
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-10-29·CVSS 5.0
CVE-2013-1739 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple memory safety issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute arbitrary code with the privileges of the user
invoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,
CVE-2013-5592)
Jordi Chancel discovered that HTML select elements could display arbitrary
content. An attacker could potentially exploit this to conduct
URL spoofing or clickjacking attacks (CVE-2013-5593)
Abhishek Arya discovered a crash when processing XSLT data in some
circumstances. An attacker could potenti
Red Hat
Mozilla: Access violation with XSLT and uninitialized data (MFSA 2013-95)
vendor_redhat·2013-10-29·CVSS 9.3
CVE-2013-5604 [CRITICAL] Mozilla: Access violation with XSLT and uninitialized data (MFSA 2013-95)
Mozilla: Access violation with XSLT and uninitialized data (MFSA 2013-95)
The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly initialize data, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via crafted documents.
GHSA
GHSA-95cx-92pf-pxrr: The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25
ghsa_unreviewed·2022-05-14
CVE-2013-5604 [HIGH] CWE-119 GHSA-95cx-92pf-pxrr: The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25
The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly initialize data, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via crafted documents.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-5604 Mozilla: Access violation with XSLT and uninitialized data (MFSA 2013-95)
bugzilla·2013-10-28·CVSS 9.3
CVE-2013-5604 [CRITICAL] CVE-2013-5604 Mozilla: Access violation with XSLT and uninitialized data (MFSA 2013-95)
CVE-2013-5604 Mozilla: Access violation with XSLT and uninitialized data (MFSA 2013-95)
Security researcher Abhishek Arya (Inferno) of the Google Chrome Security Team used the Address Sanitizer tool to discover an access violation when Extensible Stylesheet Language Transformations (XSLT) are processed with uninitialized data. This leads to a potentially exploitable crash.
In general this flaw cannot be exploited through email in the Thunderbird and Seamonkey products because scripting is disabled, but is potentially a risk in browser or browser-like contexts.
External Reference:
http://www.mozilla.org/security/announce/2013/mfsa2013-95.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Abhishek Arya as the origina
Bugzilla
CVE-2012-5604 rubygem-ldap_fluff: CloudForms authentication bypass when handling anonymous LDAP bind
bugzilla·2012-11-30·CVSS 4.3
CVE-2012-5604 [MEDIUM] CVE-2012-5604 rubygem-ldap_fluff: CloudForms authentication bypass when handling anonymous LDAP bind
CVE-2012-5604 rubygem-ldap_fluff: CloudForms authentication bypass when handling anonymous LDAP bind
Og Maciel of Red Hat reports:
After configuring my system to use ActiveDirectory as the authentication
method, I was able to login via the web ui without having to provide a
password when using Windows ADS as the LDAP authentication backend.
Discussion:
Acknowledgements:
This issue was discovered by Og Maciel of Red Hat.
---
This issue did not affect CloudForms 1.0, which did not include this component. The issue is fixed in CloudFroms 1.1. No released version of CloudFroms was affected by this issue.
---
This issue has been addressed in following products:
Red Hat Subscription Asset Manager 1.2
Via RHSA-2013:0544 https://rhn.redhat.com/errata/RHSA-2013-0544.html
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00014.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1476.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1480.htmlhttp://www.debian.org/security/2013/dsa-2788http://www.debian.org/security/2013/dsa-2797http://www.mozilla.org/security/announce/2013/mfsa2013-95.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=914017https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19091https://security.gentoo.org/glsa/201504-01http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00014.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1476.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1480.htmlhttp://www.debian.org/security/2013/dsa-2788http://www.debian.org/security/2013/dsa-2797http://www.mozilla.org/security/announce/2013/mfsa2013-95.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=914017https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19091https://security.gentoo.org/glsa/201504-01
2013-10-30
Published