int(6700)

Vulnerability Bulletins


Vulnerabilidad en Mozilla Firefox/Thunderbird/SeaMonkey

Vulnerability classification

Property Value
Confidence level official+tested
Impact Obtener acceso
Dificulty Avanzado
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer Comercial Software
Affected software Slackware Linux x86_64 -actual
Slackware Linux 13.37 x86_64
Slackware Linux 13.37
Slackware Linux -actual
RedHat Enterprise Linux Optional Productivity Application 5 server
RedHat Enterprise Linux Desktop Workstation 5 client
Red Hat Enterprise Linux Workstation Optional 6
Red Hat Enterprise Linux Workstation 6
Red Hat Enterprise Linux Server Optional 6
Red Hat Enterprise Linux Server 6
Red Hat Enterprise Linux HPC Node Optional 6
Red Hat Enterprise Linux Desktop Optional 6
Red Hat Enterprise Linux Desktop 6
Red Hat Enterprise Linux Desktop 5 client
Red Hat Enterprise Linux 5 Server
Oracle Enterprise Linux 6.2
Oracle Enterprise Linux 6
Mozilla Thunderbird ESR 10.0.5
Mozilla Thunderbird ESR 10.0.4
Mozilla Thunderbird ESR 10.0.3
Mozilla Thunderbird ESR 10.0.2
Mozilla Thunderbird 9.0
Mozilla Thunderbird 8.0
Mozilla Thunderbird 7.0.1
Mozilla Thunderbird 7.0
Mozilla Thunderbird 6.0.2
Mozilla Thunderbird 6.0.1
Mozilla Thunderbird 6.0
Mozilla Thunderbird 13.0
Mozilla Thunderbird 12.0
Mozilla Thunderbird 11.0
Mozilla Thunderbird 10.0.2
Mozilla Thunderbird 10.0.1
Mozilla Thunderbird 10.0
Mozilla SeaMonkey 2.0.11
Mozilla SeaMonkey 2.0.9
Mozilla SeaMonkey 2.0.8
Mozilla SeaMonkey 2.0.5
Mozilla SeaMonkey 2.0.3
Mozilla SeaMonkey 2.0.2
Mozilla SeaMonkey 2.0.1
Mozilla SeaMonkey 2.1
Mozilla SeaMonkey 2.0.7
Mozilla SeaMonkey 2.0.6
Mozilla SeaMonkey 2.0.4
Mozilla SeaMonkey 2.0.14
Mozilla SeaMonkey 2.0.13
Mozilla SeaMonkey 2.0.12
Mozilla SeaMonkey 2.0.10
Mozilla Firefox ESR 10.0.5
Mozilla Firefox ESR 10.0.4
Mozilla Firefox ESR 10.0.3
Mozilla Firefox ESR 10.0.2
Mozilla Firefox 13.0
Mozilla Firefox 12.0
Mozilla Firefox 11.0
Mozilla Firefox 10.0.2
Mozilla Firefox 10.0.1
Mozilla Firefox 10
Moonchild Productions Pale Moon 3.6.31
Moonchild Productions Pale Moon 3.6.30
Moonchild Productions Pale Moon 3.6.27
Moonchild Productions Pale Moon 3.6.26
Moonchild Productions Pale Moon 9.2
Moonchild Productions Pale Moon 9.1
Moonchild Productions Pale Moon 9.0.1
Moonchild Productions Pale Moon 3.6.30
Moonchild Productions Pale Moon 3.6.29
Moonchild Productions Pale Moon 12.0
Moonchild Productions Pale Moon 11.0
CentOS CentOS 5

Description

Se ha encontrado una vulnerabilidad en el modo en que XULRunner maneja contenido web con formato incorrecto.
Una página web que contenga el contenido malicioso puede causar que una aplicación enlazada contra XULRunner (como Mozilla Firefox) bloquee o ejecute código arbitrario con los privilegios del usuario que ejecuta la aplicación. (CVE-2013-0787)

Solution

Aplicar las actualizaciones de los productos, proporcionadas por el fabricante.

Standar resources

Property Value
CVE CVE-2013-0787
BID

Other resources

Boletín de seguridad de RedHat
http://rhn.redhat.com/errata/RHSA-2013-0614.html

Boletín de seguridad de Security Focus
http://www.securityfocus.com/bid/58391

Version history

Version Comments Date
1.0 Aviso emitido 2013-03-12