CVE-2013-0796
Description
The WebGL subsystem in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 on Linux does not properly interact with Mesa drivers, which allows remote attackers to execute arbitrary code or cause a denial of service (free of unallocated memory) via unspecified vectors.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@mozilla.org — https://bugzilla.mozilla.org/show_bug.cgi?id=838413
Vendor advisory: security@mozilla.org — https://bugzilla.mozilla.org/show_bug.cgi?id=827106
Vendor advisory: security@mozilla.org — http://www.mozilla.org/security/announce/2013/mfsa2013-35.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| linux-kernel | - | not-affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| mozilla | firefox | {"endExcluding":"20.0"} | 20.0 |
| mozilla | thunderbird | {"startIncluding":"17.0","endExcluding":"17.0.5"} | 17.0.5 |
| mozilla | thunderbird_esr | {"startIncluding":"17.0","endExcluding":"17.0.5"} | 17.0.5 |
| mozilla | seamonkey | {"endExcluding":"2.17"} | 2.17 |
References
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.html
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00019.html
- http://lists.opensuse.org/opensuse-updates/2013-06/msg00012.html
- http://rhn.redhat.com/errata/RHSA-2013-0696.html
- http://rhn.redhat.com/errata/RHSA-2013-0697.html
- http://www.debian.org/security/2013/dsa-2699
- http://www.mozilla.org/security/announce/2013/mfsa2013-35.html
- http://www.ubuntu.com/usn/USN-1791-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=827106
- https://bugzilla.mozilla.org/show_bug.cgi?id=838413
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.html
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00019.html
- http://lists.opensuse.org/opensuse-updates/2013-06/msg00012.html
- http://rhn.redhat.com/errata/RHSA-2013-0696.html
- http://rhn.redhat.com/errata/RHSA-2013-0697.html
- http://www.debian.org/security/2013/dsa-2699
- http://www.mozilla.org/security/announce/2013/mfsa2013-35.html
- http://www.ubuntu.com/usn/USN-1791-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=827106
- https://bugzilla.mozilla.org/show_bug.cgi?id=838413
Verify integrity in audit chain (admin only). AS-IS.