Vulnerability Description
Use-after-free vulnerability in the mozilla::dom::HTMLMediaElement::LookupMediaElementURITable function in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted web site.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | <= 21.0 |
| Mozilla | Thunderbird | <= 17.0.6 |
| Mozilla | Thunderbird Esr | 17.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html
- http://rhn.redhat.com/errata/RHSA-2013-0981.html
- http://rhn.redhat.com/errata/RHSA-2013-0982.html
- http://www.debian.org/security/2013/dsa-2716
- http://www.debian.org/security/2013/dsa-2720
- http://www.mozilla.org/security/announce/2013/mfsa2013-50.htmlVendor Advisory
- http://www.securityfocus.com/bid/60766
- http://www.ubuntu.com/usn/USN-1890-1
- http://www.ubuntu.com/usn/USN-1891-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=865537
FAQ
What is CVE-2013-1684?
CVE-2013-1684 is a vulnerability with a CVSS score of 9.3 (HIGH). Use-after-free vulnerability in the mozilla::dom::HTMLMediaElement::LookupMediaElementURITable function in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and T...
How severe is CVE-2013-1684?
CVE-2013-1684 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-1684?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Thunderbird, Mozilla Thunderbird Esr.