int(6700)

Boletines de Vulnerabilidades


Vulnerabilidad en Mozilla Firefox/Thunderbird/SeaMonkey

Clasificación de la vulnerabilidad

Propiedad Valor
Nivel de Confianza official+tested
Impacto Obtener acceso
Dificultad Avanzado
Requerimientos del atacante Acceso remoto sin cuenta a un servicio estandar

Información sobre el sistema

Propiedad Valor
Fabricante afectado Comercial Software
Software afectado Slackware Linux x86_64 -actual
Slackware Linux 13.37 x86_64
Slackware Linux 13.37
Slackware Linux -actual
RedHat Enterprise Linux Optional Productivity Application 5 server
RedHat Enterprise Linux Desktop Workstation 5 client
Red Hat Enterprise Linux Workstation Optional 6
Red Hat Enterprise Linux Workstation 6
Red Hat Enterprise Linux Server Optional 6
Red Hat Enterprise Linux Server 6
Red Hat Enterprise Linux HPC Node Optional 6
Red Hat Enterprise Linux Desktop Optional 6
Red Hat Enterprise Linux Desktop 6
Red Hat Enterprise Linux Desktop 5 client
Red Hat Enterprise Linux 5 Server
Oracle Enterprise Linux 6.2
Oracle Enterprise Linux 6
Mozilla Thunderbird ESR 10.0.5
Mozilla Thunderbird ESR 10.0.4
Mozilla Thunderbird ESR 10.0.3
Mozilla Thunderbird ESR 10.0.2
Mozilla Thunderbird 9.0
Mozilla Thunderbird 8.0
Mozilla Thunderbird 7.0.1
Mozilla Thunderbird 7.0
Mozilla Thunderbird 6.0.2
Mozilla Thunderbird 6.0.1
Mozilla Thunderbird 6.0
Mozilla Thunderbird 13.0
Mozilla Thunderbird 12.0
Mozilla Thunderbird 11.0
Mozilla Thunderbird 10.0.2
Mozilla Thunderbird 10.0.1
Mozilla Thunderbird 10.0
Mozilla SeaMonkey 2.0.11
Mozilla SeaMonkey 2.0.9
Mozilla SeaMonkey 2.0.8
Mozilla SeaMonkey 2.0.5
Mozilla SeaMonkey 2.0.3
Mozilla SeaMonkey 2.0.2
Mozilla SeaMonkey 2.0.1
Mozilla SeaMonkey 2.1
Mozilla SeaMonkey 2.0.7
Mozilla SeaMonkey 2.0.6
Mozilla SeaMonkey 2.0.4
Mozilla SeaMonkey 2.0.14
Mozilla SeaMonkey 2.0.13
Mozilla SeaMonkey 2.0.12
Mozilla SeaMonkey 2.0.10
Mozilla Firefox ESR 10.0.5
Mozilla Firefox ESR 10.0.4
Mozilla Firefox ESR 10.0.3
Mozilla Firefox ESR 10.0.2
Mozilla Firefox 13.0
Mozilla Firefox 12.0
Mozilla Firefox 11.0
Mozilla Firefox 10.0.2
Mozilla Firefox 10.0.1
Mozilla Firefox 10
Moonchild Productions Pale Moon 3.6.31
Moonchild Productions Pale Moon 3.6.30
Moonchild Productions Pale Moon 3.6.27
Moonchild Productions Pale Moon 3.6.26
Moonchild Productions Pale Moon 9.2
Moonchild Productions Pale Moon 9.1
Moonchild Productions Pale Moon 9.0.1
Moonchild Productions Pale Moon 3.6.30
Moonchild Productions Pale Moon 3.6.29
Moonchild Productions Pale Moon 12.0
Moonchild Productions Pale Moon 11.0
CentOS CentOS 5

Descripción

Se ha encontrado una vulnerabilidad en el modo en que XULRunner maneja contenido web con formato incorrecto.
Una página web que contenga el contenido malicioso puede causar que una aplicación enlazada contra XULRunner (como Mozilla Firefox) bloquee o ejecute código arbitrario con los privilegios del usuario que ejecuta la aplicación. (CVE-2013-0787)

Solución

Aplicar las actualizaciones de los productos, proporcionadas por el fabricante.

Identificadores estándar

Propiedad Valor
CVE CVE-2013-0787
BID

Recursos adicionales

Boletín de seguridad de RedHat
http://rhn.redhat.com/errata/RHSA-2013-0614.html

Boletín de seguridad de Security Focus
http://www.securityfocus.com/bid/58391

Histórico de versiones

Versión Comentario Fecha
1.0 Aviso emitido 2013-03-12