First published: Wed Jun 26 2013(Updated: )
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not prevent the inclusion of body data in an XMLHttpRequest HEAD request, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web site.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <=21.0 | |
Mozilla Firefox | =19.0 | |
Mozilla Firefox | =19.0.1 | |
Mozilla Firefox | =19.0.2 | |
Mozilla Firefox | =20.0 | |
Mozilla Firefox | =20.0.1 | |
Mozilla Firefox ESR | =17.0 | |
Mozilla Firefox ESR | =17.0.1 | |
Mozilla Firefox ESR | =17.0.2 | |
Mozilla Firefox ESR | =17.0.3 | |
Mozilla Firefox ESR | =17.0.4 | |
Mozilla Firefox ESR | =17.0.5 | |
Mozilla Firefox ESR | =17.0.6 | |
Mozilla Thunderbird | <=17.0.6 | |
Mozilla Thunderbird | =17.0 | |
Mozilla Thunderbird | =17.0.1 | |
Mozilla Thunderbird | =17.0.2 | |
Mozilla Thunderbird | =17.0.3 | |
Mozilla Thunderbird | =17.0.4 | |
Mozilla Thunderbird | =17.0.5 | |
Mozilla Thunderbird ESR | =17.0 | |
Mozilla Thunderbird ESR | =17.0.1 | |
Mozilla Thunderbird ESR | =17.0.2 | |
Mozilla Thunderbird ESR | =17.0.3 | |
Mozilla Thunderbird ESR | =17.0.4 | |
Mozilla Thunderbird ESR | =17.0.5 | |
Mozilla Thunderbird ESR | =17.0.6 | |
Mozilla Firefox | =17.0 | |
Mozilla Firefox | =17.0.1 | |
Mozilla Firefox | =17.0.2 | |
Mozilla Firefox | =17.0.3 | |
Mozilla Firefox | =17.0.4 | |
Mozilla Firefox | =17.0.5 | |
Mozilla Firefox | =17.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1692 has a moderate severity as it allows for potential cross-site request forgery (CSRF) attacks.
To fix CVE-2013-1692, update affected versions of Mozilla Firefox, Firefox ESR, and Thunderbird to the latest version.
CVE-2013-1692 affects Mozilla Firefox versions before 22.0, Firefox ESR versions before 17.0.7, and Thunderbird versions before 17.0.7.
CVE-2013-1692 impacts Mozilla Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR applications.
The consequences of CVE-2013-1692 include the potential for attackers to manipulate user actions through cross-site request forgery attacks.