Summary
This host is installed with Mozilla Firefox/Thunderbird/Seamonkey and is prone to multiple vulnerabilities.
Impact
Successful exploitation could allow attackers to inject scripts, bypass certain security restrictions, cause a denial of service or execute arbitrary code in the context of the browser.
Impact Level: System/Application
Solution
Upgrade to Mozilla Firefox version 18.0 or ESR version 17.0.2 or later, For updates refer to http://www.mozilla.com/en-US/firefox/all.html
Upgrade to SeaMonkey version to 2.15 or later,
http://www.mozilla.org/projects/seamonkey/
Upgrade to Thunderbird version to 17.0.2 or ESR 17.0.2 or later, http://www.mozilla.org/en-US/thunderbird/
Insight
- An error exists within the 'nsSOCKSSocketInfo::ConnectToProxy()' when handling SSL connection threads.
- An error when parsing height and width values of a canvas element.
- An error within the 'Object.prototype.__proto__()' can be exploited to bypass Chrome Object Wrappers (COW).
- Unspecified error in the browser engine can be exploited to corrupt memory.
- An error exists due to the AutoWrapperChanger class not keeping certain objects alive during garbage collection.
Affected
SeaMonkey version before 2.15 on Mac OS X
Thunderbird version before 17.0.2 on Mac OS X
Mozilla Firefox version before 18.0 on Mac OS X
Thunderbird ESR version 17.x before 17.0.2 on Mac OS X Mozilla Firefox ESR version 17.x before 17.0.2 on Mac OS X
References
- http://secunia.com/advisories/51752/
- http://securitytracker.com/id?1027955
- http://securitytracker.com/id?1027957
- http://securitytracker.com/id?1027958
- http://www.mozilla.org/security/announce/2013/mfsa2013-03.html
- http://www.mozilla.org/security/announce/2013/mfsa2013-07.html
- http://www.mozilla.org/security/announce/2013/mfsa2013-08.html
- http://www.mozilla.org/security/announce/2013/mfsa2013-10.html
- http://www.mozilla.org/security/announce/2013/mfsa2013-13.html
- http://www.mozilla.org/security/announce/2013/mfsa2013-14.html
- http://www.mozilla.org/security/announce/2013/mfsa2013-18.html
- http://www.mozilla.org/security/announce/2013/mfsa2013-19.html
- http://www.osvdb.org/89012
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2013-0745, CVE-2013-0747, CVE-2013-0752, CVE-2013-0755, CVE-2013-0756, CVE-2013-0757, CVE-2013-0764, CVE-2013-0768 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Adobe Flash Player Buffer Overflow Vulnerability - Apr14 (Linux)
- Adobe Air Remote Code Execution Vulnerability -June13 (Mac OS X)
- Adobe Acrobat and Reader PDF Handling Multiple Vulnerabilities (Windows)
- Adobe Acrobat and Reader Multiple Vulnerabilities -July10 (Windows)
- Adobe Acrobat Multiple Unspecified Vulnerabilities -01 May13 (Windows)