First published: Wed Apr 03 2013(Updated: )
The WebGL subsystem in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 on Linux does not properly interact with Mesa drivers, which allows remote attackers to execute arbitrary code or cause a denial of service (free of unallocated memory) via unspecified vectors.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Mozilla Firefox | <20.0 | |
Linux Kernel | ||
All of | ||
Mozilla Firefox | >=17.0<17.0.5 | |
Linux Kernel | ||
All of | ||
Mozilla Thunderbird | >=17.0<17.0.5 | |
Linux Kernel | ||
All of | ||
Mozilla Thunderbird ESR | >=17.0<17.0.5 | |
Linux Kernel | ||
All of | ||
Mozilla SeaMonkey | <2.17 | |
Linux Kernel | ||
Mozilla Firefox | <20.0 | |
Linux Kernel | ||
Mozilla Firefox ESR | >=17.0<17.0.5 | |
Mozilla Thunderbird | >=17.0<17.0.5 | |
Mozilla Thunderbird ESR | >=17.0<17.0.5 | |
Mozilla SeaMonkey | <2.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0796 has a high severity due to its potential to allow remote attackers to execute arbitrary code.
To mitigate CVE-2013-0796, upgrade to Mozilla Firefox version 20.0 or later, or Mozilla Thunderbird, Thunderbird ESR, and SeaMonkey to their updated versions addressing this vulnerability.
CVE-2013-0796 affects Mozilla Firefox prior to 20.0, Firefox ESR versions prior to 17.0.5, Thunderbird versions prior to 17.0.5, Thunderbird ESR versions prior to 17.0.5, and SeaMonkey versions prior to 2.17 on Linux.
CVE-2013-0796 impacts Mozilla Firefox, Firefox ESR, Thunderbird, Thunderbird ESR, and SeaMonkey when running on Linux.
Yes, CVE-2013-0796 can lead to denial of service in addition to allowing remote code execution.