MEDIUM · 5.8

CVE-2013-5611

Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing ...

Vulnerability Description

Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing of page navigation.

CVSS Score

5.8

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
OracleSolaris11.3
FedoraprojectFedora19
CanonicalUbuntu Linux12.04
SuseLinux Enterprise Desktop11
SuseLinux Enterprise Server11
SuseLinux Enterprise Software Development Kit11
OpensuseOpensuse13.1
Opensuse ProjectOpensuse11.4
MozillaFirefox<= 25.0.1

References

FAQ

What is CVE-2013-5611?

CVE-2013-5611 is a vulnerability with a CVSS score of 5.8 (MEDIUM). Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing ...

How severe is CVE-2013-5611?

CVE-2013-5611 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-5611?

Check the references section above for vendor advisories and patch information. Affected products include: Oracle Solaris, Fedoraproject Fedora, Canonical Ubuntu Linux, Suse Linux Enterprise Desktop, Suse Linux Enterprise Server.