CVE-2013-1679: Use After Free
Use-after-free vulnerability in the mozilla::plugins::child::geturlnotify function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1679?
CVE-2013-1679 has a severity rating that indicates a significant risk of arbitrary code execution and denial of service.
How do I fix CVE-2013-1679?
To fix CVE-2013-1679, update Mozilla Firefox, Thunderbird, or the relevant ESR versions to a patched version above 21.0 or 17.0.6.
Which versions are affected by CVE-2013-1679?
CVE-2013-1679 affects Mozilla Firefox versions before 21.0 and Mozilla Thunderbird versions before 17.0.6.
What types of attacks can exploit CVE-2013-1679?
CVE-2013-1679 can be exploited by remote attackers to execute arbitrary code or cause a denial of service.
Is CVE-2013-1679 a common vulnerability?
CVE-2013-1679 represents a known vulnerability within common Mozilla software, making it relatively prevalent among users of those applications.