First published: Sun Jan 13 2013(Updated: )
Use-after-free vulnerability in the mozVibrate implementation in the Vibrate library in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via vectors related to the domDoc pointer.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <17.0.2 | |
Mozilla Firefox | <18.0 | |
Mozilla SeaMonkey | <2.15 | |
Mozilla Thunderbird | <17.0.2 | |
Mozilla Thunderbird ESR | <17.0.2 | |
openSUSE | =11.4 | |
openSUSE | =12.1 | |
openSUSE | =12.2 | |
SUSE Linux Enterprise Desktop with Beagle | =10-sp4 | |
SUSE Linux Enterprise Desktop with Beagle | =11-sp2 | |
SUSE Linux Enterprise Server | =10-sp4 | |
SUSE Linux Enterprise Server | =11-sp2 | |
suse linux enterprise server vmware | =11-sp2 | |
SUSE Linux Enterprise Software Development Kit | =10-sp4 | |
SUSE Linux Enterprise Software Development Kit | =11-sp2 | |
Ubuntu | =10.04 | |
Ubuntu | =11.10 | |
Ubuntu | =12.04 | |
Ubuntu | =12.10 | |
Mozilla Firefox ESR | <17.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0755 is classified as a critical vulnerability due to its ability to allow remote attackers to execute arbitrary code.
The recommended fix for CVE-2013-0755 is to update affected software to the latest version that is not vulnerable.
CVE-2013-0755 affects Mozilla Firefox versions before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird versions before 17.0.2, and SeaMonkey before 2.15.
CVE-2013-0755 can be exploited through use-after-free vulnerabilities in the mozVibrate implementation within the browser's Vibrate library.
There is no known workaround for CVE-2013-0755; upgrading to a patched version is the only effective remediation.