FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-1690

This CVE name corresponds to:

Entered Topic
2013-06-26 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-1690
Phase Assigned(20130213)

Description

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.

References

Source Reference
CONFIRM http://www.mozilla.org/security/announce/2013/mfsa2013-53.html
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=857883
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=901365
DEBIAN DSA-2716
DEBIAN DSA-2720
REDHAT RHSA-2013:0981
REDHAT RHSA-2013:0982
SUSE SUSE-SU-2013:1152
SUSE SUSE-SU-2013:1153
SUSE openSUSE-SU-2013:1140
SUSE openSUSE-SU-2013:1141
SUSE openSUSE-SU-2013:1142
SUSE openSUSE-SU-2013:1143
UBUNTU USN-1890-1
UBUNTU USN-1891-1
OVAL oval:org.mitre.oval:def:16996