CVE-2013-1670

The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 does not prevent acquisition of chrome privileges during calls to content level constructors, which allows remote attackers to bypass certain read-only restrictions and conduct cross-site scripting (XSS) attacks via a crafted web site.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.html
http://rhn.redhat.com/errata/RHSA-2013-0820.html
http://rhn.redhat.com/errata/RHSA-2013-0821.html
http://www.debian.org/security/2013/dsa-2699
http://www.exploit-db.com/exploits/34363
http://www.mandriva.com/security/advisories?name=MDVSA-2013:165
http://www.mozilla.org/security/announce/2013/mfsa2013-42.html Vendor Advisory
http://www.osvdb.org/93427
http://www.securityfocus.com/bid/59865
http://www.ubuntu.com/usn/USN-1822-1
http://www.ubuntu.com/usn/USN-1823-1
https://bugzilla.mozilla.org/show_bug.cgi?id=853709
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17046
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.html
http://rhn.redhat.com/errata/RHSA-2013-0820.html
http://rhn.redhat.com/errata/RHSA-2013-0821.html
http://www.debian.org/security/2013/dsa-2699
http://www.exploit-db.com/exploits/34363
http://www.mandriva.com/security/advisories?name=MDVSA-2013:165
http://www.mozilla.org/security/announce/2013/mfsa2013-42.html Vendor Advisory
http://www.osvdb.org/93427
http://www.securityfocus.com/bid/59865
http://www.ubuntu.com/usn/USN-1822-1
http://www.ubuntu.com/usn/USN-1823-1
https://bugzilla.mozilla.org/show_bug.cgi?id=853709
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17046
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:19.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:19.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:19.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:20.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:mozilla:firefox:17.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:17.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:17.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:17.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:17.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:17.0.5:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.4:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:mozilla:thunderbird_esr:17.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.5:*:*:*:*:*:*:*

History

21 Nov 2024, 01:50

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html - () http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html -
References () http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html - () http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html -
References () http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html - () http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html -
References () http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.html - () http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.html -
References () http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.html - () http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0820.html - () http://rhn.redhat.com/errata/RHSA-2013-0820.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0821.html - () http://rhn.redhat.com/errata/RHSA-2013-0821.html -
References () http://www.debian.org/security/2013/dsa-2699 - () http://www.debian.org/security/2013/dsa-2699 -
References () http://www.exploit-db.com/exploits/34363 - () http://www.exploit-db.com/exploits/34363 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2013:165 - () http://www.mandriva.com/security/advisories?name=MDVSA-2013:165 -
References () http://www.mozilla.org/security/announce/2013/mfsa2013-42.html - Vendor Advisory () http://www.mozilla.org/security/announce/2013/mfsa2013-42.html - Vendor Advisory
References () http://www.osvdb.org/93427 - () http://www.osvdb.org/93427 -
References () http://www.securityfocus.com/bid/59865 - () http://www.securityfocus.com/bid/59865 -
References () http://www.ubuntu.com/usn/USN-1822-1 - () http://www.ubuntu.com/usn/USN-1822-1 -
References () http://www.ubuntu.com/usn/USN-1823-1 - () http://www.ubuntu.com/usn/USN-1823-1 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=853709 - () https://bugzilla.mozilla.org/show_bug.cgi?id=853709 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17046 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17046 -

21 Oct 2024, 13:55

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox_esr:17.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:17.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:17.0:*:*:*:*:*:*:*

21 Oct 2024, 13:11

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox_esr:17.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:17.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:17.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:17.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:17.0.2:*:*:*:*:*:*:*

Information

Published : 2013-05-16 11:45

Updated : 2024-11-21 01:50


NVD link : CVE-2013-1670

Mitre link : CVE-2013-1670

CVE.ORG link : CVE-2013-1670


JSON object : View

Products Affected

mozilla

  • firefox
  • thunderbird
  • thunderbird_esr
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-264

Permissions, Privileges, and Access Controls