Mozilla Firefox < 18.0 Multiple Vulnerabilities

High Nessus Network Monitor Plugin ID 6668

Synopsis

The remote host has a web browser installed that is vulnerable to multiple attack vectors.

Description

Versions of Firefox prior to 18.0 are potentially affected by the following security issues :

- Multiple, unspecified use-after-free, out-of-bounds read and buffer overflow errors exist. (CVE-2012-5829, CVE-2013-0760, CVE-2013-0761, CVE-2013-0762, CVE-2013-0763, CVE-2013-0766, CVE-2013-0767, CVE-2013-0771)
- Two intermediate certificates were improperly issued by TURKTRUST certificate authority. (CVE-2013-0743)
- A use-after-free error exists related to displaying HTML tables with many columns and column groups. (CVE-2013-0744)
- An error exists related to the 'AutoWrapperChanger' class that does not properly manage objects during garbage collection. (CVE-2012-0745)
- An error exists related to 'jsval', 'quickstubs', and compartmental mismatches that can lead potentially exploitable crashes. (CVE-2013-0746)
- Errors exist related to events in the plugin handler that can allow same-origin policy bypass. (CVE-2013-0747)
- An error related to the 'toString' method of XBL objects can lead to address information leakage. (CVE-2013-0748)
- An unspecified memory corruption issue exists. (CVE-2013-0749, CVE-2013-0769, CVE-2013-0770)
- A buffer overflow exists related to JavaScript string concatenation. (CVE-2013-0750)
- An error exists related to multiple XML bindings with SVG content, contained in XBL files. (CVE-2013-0752)
- A use-after-free error exists related to 'XMLSerializer' and 'serializeToStream'. (CVE-2013-0753)
- A use-after-free error exists related to garbage collection and 'ListenManager'. (CVE-2013-0754)
- A use-after-free error exists related to the 'Vibrate' library and 'domDoc'. (CVE-2013-0755)
- A use-after-free error exists related to JavaScript 'Proxy' objects. (CVE-2013-0756)
- 'Chrome Object Wrappers' (COW) can be bypassed by changing object prototypes and can allow arbitrary code execution. (CVE-2013-0757)
- An error related to SVG elements and plugins can allow privilege escalation. (CVE-2013-0758)
- An error exists related to the address bar that can allow URL spoofing attacks. (CVE-2013-0759)
- An error exists related to SSL and threading that can result in potentially exploitable crashes. (CVE-2013-0764)
- An error exists related to 'Canvas' and bad height or width values passed to it from HTML. (CVE-2013-0768)

Solution

Upgrade to Firefox 18.0 or later.

See Also

http://www.mozilla.org/security/announce/2012/mfsa2013-01.html

http://www.mozilla.org/security/announce/2012/mfsa2013-02.html

http://www.mozilla.org/security/announce/2012/mfsa2013-03.html

http://www.mozilla.org/security/announce/2012/mfsa2013-04.html

http://www.mozilla.org/security/announce/2012/mfsa2013-05.html

http://www.mozilla.org/security/announce/2012/mfsa2013-06.html

http://www.mozilla.org/security/announce/2012/mfsa2013-07.html

http://www.mozilla.org/security/announce/2012/mfsa2013-08.html

http://www.mozilla.org/security/announce/2012/mfsa2013-09.html

http://www.mozilla.org/security/announce/2012/mfsa2013-10.html

http://www.mozilla.org/security/announce/2012/mfsa2013-11.html

http://www.mozilla.org/security/announce/2012/mfsa2013-12.html

http://www.mozilla.org/security/announce/2012/mfsa2013-13.html

http://www.mozilla.org/security/announce/2012/mfsa2013-14.html

http://www.mozilla.org/security/announce/2012/mfsa2013-15.html

http://www.mozilla.org/security/announce/2012/mfsa2013-16.html

http://www.mozilla.org/security/announce/2012/mfsa2013-17.html

http://www.mozilla.org/security/announce/2012/mfsa2013-18.html

http://www.mozilla.org/security/announce/2012/mfsa2013-19.html

http://www.mozilla.org/security/announce/2012/mfsa2013-20.html

Plugin Details

Severity: High

ID: 6668

Family: Web Clients

Published: 2013/01/15

Modified: 2016/12/06

Dependencies: 9131

Nessus ID: 63551, 63661

Risk Information

Risk Factor: High

CVSSv2

Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

CVSSv3

Base Score: 8.1

Temporal Score: 7.7

Vector: CVSS3#AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS3#E:X/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:mozilla:firefox

Patch Publication Date: 2013/01/08

Vulnerability Publication Date: 2013/01/08

Exploitable With

Metasploit (Firefox 17.0.1 Flash Privileged Code Injection)

Reference Information

CVE: CVE-2013-0744, CVE-2013-0745, CVE-2013-0746, CVE-2013-0747, CVE-2013-0748, CVE-2013-0749, CVE-2013-0750, CVE-2013-0751, CVE-2013-0752, CVE-2013-0753, CVE-2013-0754, CVE-2013-0755, CVE-2013-0756, CVE-2013-0757, CVE-2013-0758, CVE-2013-0759, CVE-2013-0760, CVE-2013-0761, CVE-2013-0763, CVE-2013-0764, CVE-2013-0766, CVE-2013-0767, CVE-2013-0768, CVE-2013-0769, CVE-2013-0770, CVE-2013-0771

BID: 56151, 57193, 57194, 57195, 57196, 57197, 57198, 57199, 57203, 57204, 57205, 57207, 57209, 57211, 57213, 57215, 57217, 57218, 57228, 57232, 57234, 57235, 57236, 57238, 57240, 57241, 57244, 57258, 57260