First published: Thu May 16 2013(Updated: )
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <=20.0.1 | |
Mozilla Firefox | =19.0 | |
Mozilla Firefox | =19.0.1 | |
Mozilla Firefox | =19.0.2 | |
Mozilla Firefox | =20.0 | |
Mozilla Firefox ESR | =17.0 | |
Mozilla Firefox ESR | =17.0.1 | |
Mozilla Firefox ESR | =17.0.2 | |
Mozilla Firefox ESR | =17.0.3 | |
Mozilla Firefox ESR | =17.0.4 | |
Mozilla Firefox ESR | =17.0.5 | |
Mozilla Thunderbird | <=17.0.5 | |
Mozilla Thunderbird | =17.0 | |
Mozilla Thunderbird | =17.0.1 | |
Mozilla Thunderbird | =17.0.2 | |
Mozilla Thunderbird | =17.0.3 | |
Mozilla Thunderbird | =17.0.4 | |
Mozilla Thunderbird ESR | =17.0 | |
Mozilla Thunderbird ESR | =17.0.1 | |
Mozilla Thunderbird ESR | =17.0.2 | |
Mozilla Thunderbird ESR | =17.0.3 | |
Mozilla Thunderbird ESR | =17.0.4 | |
Mozilla Thunderbird ESR | =17.0.5 | |
Mozilla Firefox | =17.0 | |
Mozilla Firefox | =17.0.1 | |
Mozilla Firefox | =17.0.2 | |
Mozilla Firefox | =17.0.3 | |
Mozilla Firefox | =17.0.4 | |
Mozilla Firefox | =17.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0801 has a moderate severity rating as it allows remote attackers to cause denial of service due to memory corruption.
To fix CVE-2013-0801, update your Mozilla Firefox, Firefox ESR, or Thunderbird to the latest version available.
CVE-2013-0801 affects Mozilla Firefox versions before 21.0, Firefox ESR 17.x before 17.0.6, and various versions of Thunderbird.
While CVE-2013-0801 is primarily a denial of service vulnerability, there is potential for it to lead to remote code execution due to memory corruption.
The best course of action for CVE-2013-0801 is to update to the latest version, as no specific workaround is recommended.