First published: Wed Aug 07 2013(Updated: )
Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in Mozilla Firefox before 23.0 on Windows allow local users to gain privileges via a Trojan horse DLL in the default downloads directory. NOTE: this issue exists because of an incomplete fix for CVE-2012-4206.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <=22.0 | |
Firefox | =19.0 | |
Firefox | =19.0.1 | |
Firefox | =19.0.2 | |
Firefox | =20.0 | |
Firefox | =20.0.1 | |
Firefox | =21.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1715 is classified as a moderate severity vulnerability.
To mitigate CVE-2013-1715, upgrade to Mozilla Firefox version 23.0 or later.
CVE-2013-1715 affects Mozilla Firefox versions prior to 23.0, including 19.0 to 22.0.
CVE-2013-1715 involves multiple untrusted search path vulnerabilities that allow local users to execute a Trojan horse DLL.
Yes, the fix for CVE-2013-1715 was implemented in Mozilla Firefox version 23.0.