First published: Wed Dec 11 2013(Updated: )
Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code by triggering improper garbage collection.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <26.0 | |
Mozilla Firefox ESR | >=24.0<24.2 | |
Mozilla SeaMonkey | <2.23 | |
Mozilla Thunderbird | <24.2 | |
Fedoraproject Fedora | =18 | |
Fedoraproject Fedora | =19 | |
Fedoraproject Fedora | =20 | |
SUSE Linux Enterprise Software Development Kit | =11.0-sp3 | |
openSUSE | =12.2 | |
openSUSE | =12.3 | |
openSUSE | =13.1 | |
SUSE Linux Enterprise Desktop | =11-sp3 | |
SUSE Linux Enterprise Server | =11-sp3 | |
SUSE Linux Enterprise Server | =11-sp3 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =12.10 | |
Ubuntu Linux | =13.04 | |
Ubuntu Linux | =13.10 | |
redhat enterprise Linux desktop | =5.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux eus | =6.5 | |
redhat enterprise Linux server | =5.0 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server aus | =6.5 | |
redhat enterprise Linux server eus | =6.5 | |
redhat enterprise Linux server tus | =6.5 | |
redhat enterprise Linux workstation | =5.0 | |
redhat enterprise Linux workstation | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5618 is classified as a high severity vulnerability that can lead to remote code execution.
To fix CVE-2013-5618, update to Mozilla Firefox version 26.0 or later, or the respective updated versions of Firefox ESR, Thunderbird, or SeaMonkey.
CVE-2013-5618 affects Mozilla Firefox versions before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23.
Yes, remote attackers can exploit CVE-2013-5618 by triggering specific actions in the vulnerable versions of the software.
CVE-2013-5618 impacts various software including Mozilla Firefox, Firefox ESR, Thunderbird, SeaMonkey, and several versions of Fedora and SUSE.