CVE-2013-5598: High severity firefox esr vulnerability
PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5598?
CVE-2013-5598 is considered a high-severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2013-5598?
To fix CVE-2013-5598, update Mozilla Firefox to version 25.0 or later, or Firefox ESR to version 24.1 or later.
Who is affected by CVE-2013-5598?
CVE-2013-5598 affects Mozilla Firefox versions prior to 25.0 and Firefox ESR versions before 24.1.
What kind of attack can exploit CVE-2013-5598?
CVE-2013-5598 can be exploited to read arbitrary files or execute arbitrary JavaScript code with chrome privileges.
When was CVE-2013-5598 discovered?
CVE-2013-5598 was disclosed in November 2013.