CVE-2013-1726: Medium severity mozilla thunderbird vulnerability
Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1726?
CVE-2013-1726 has been classified as a moderate severity vulnerability due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2013-1726?
To resolve CVE-2013-1726, update your Mozilla Firefox or Thunderbird to versions 24.0 or later, or the latest Thunderbird ESR 17.0.9, and SeaMonkey 2.21.
Who is affected by CVE-2013-1726?
CVE-2013-1726 affects users of Mozilla Firefox versions prior to 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21.
Can remote attackers exploit CVE-2013-1726?
No, CVE-2013-1726 is a local privilege escalation vulnerability that requires physical or local access to the system.
Is there a workaround for CVE-2013-1726?
There are no specific workarounds for CVE-2013-1726; updating to a fixed version is the advisable action.