{
  "threat_severity" : "Critical",
  "public_date" : "2013-02-19T00:00:00Z",
  "bugzilla" : {
    "description" : "Mozilla: Wrapped WebIDL objects can be wrapped again (MFSA 2013-23)",
    "id" : "911838",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=911838"
  },
  "cvss" : {
    "cvss_base_score" : "6.8",
    "cvss_scoring_vector" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
    "status" : "draft"
  },
  "details" : [ "Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 do not prevent multiple wrapping of WebIDL objects, which allows remote attackers to bypass intended access restrictions via unspecified vectors." ],
  "statement" : "This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6",
  "acknowledgement" : "Red Hat would like to thank Mozilla project for reporting this issue.",
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Not affected",
    "package_name" : "firefox",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Not affected",
    "package_name" : "thunderbird",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "firefox",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "thunderbird",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2013-0765\nhttps://nvd.nist.gov/vuln/detail/CVE-2013-0765\nhttp://www.mozilla.org/security/announce/2013/mfsa2013-23.html" ],
  "name" : "CVE-2013-0765",
  "csaw" : false
}