You are here

CVE-2013-1681

Vincent (CVE) Danen's picture
Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

Details Source

Mitre

Public Date

2013-05-14 00:00:00

Impact

Critical

Bugzilla

CVE-2013-1676 CVE-2013-1677 CVE-2013-1678 CVE-2013-1679 CVE-2013-1680 CVE-2013-1681 Mozilla: Memory corruption found using Address Sanitizer (MFSA 2013-48)

Bugzilla ID

962 603

CVSS Status

verified

Base Score

6.80

Base Metrics

AV:N/AC:M/Au:N/C:P/I:P/A:P

Acknowledgements

Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Abhishek Arya as the original reporter.

External References

http://www.mozilla.org/security/announce/2013/mfsa2013-48.html

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 5 (thunderbird) RHSA-2013:0821 2013-05-14
Red Hat Enterprise Linux 5 (firefox) RHSA-2013:0820 2013-05-14
Red Hat Enterprise Linux Optional Productivity Applications (v. 5 server) (thunderbird) RHSA-2013:0821 2013-05-14
Red Hat Enterprise Linux 6 (firefox) RHSA-2013:0820 2013-05-14
Red Hat Enterprise Linux 6 (thunderbird) RHSA-2013:0821 2013-05-14

Affected Packages State

Platform Package State
Red Hat Enterprise Linux version 6 xulrunner 17.0.6-2.el6_4 Fixed
Red Hat Enterprise Linux version 5 xulrunner 17.0.6-1.el5_9 Fixed