{"id":"MGASA-2013-0189","summary":"Updated Firefox and Thunderbird packages fix multiple vulnerabilities","details":"Updated firefox packages fix security vulnerabilities..\n\nSeveral flaws were found in the processing of malformed web content. A web\npage containing malicious content could cause Firefox to crash or,\npotentially, execute arbitrary code with the privileges of the user running\nFirefox (CVE-2013-1682, CVE-2013-1684, CVE-2013-1685, CVE-2013-1686,\nCVE-2013-1687, CVE-2013-1690).\n\nIt was found that Firefox allowed data to be sent in the body of\nXMLHttpRequest (XHR) HEAD requests. In some cases this could allow\nattackers to conduct Cross-Site Request Forgery (CSRF) attacks\n(CVE-2013-1692).\n\nTiming differences in the way Firefox processed SVG image files could\nallow an attacker to read data across domains, potentially leading to\ninformation disclosure (CVE-2013-1693).\n\nTwo flaws were found in the way Firefox implemented some of its internal\nstructures (called wrappers). An attacker could use these flaws to bypass\nsome restrictions placed on them. This could lead to unexpected behavior or\na potentially exploitable crash (CVE-2013-1694, CVE-2013-1697).\n\n\nUpdated thunderbird packages fix security vulnerabilities..\n\nSeveral flaws were found in the processing of malformed content. Malicious\ncontent could cause Thunderbird to crash or, potentially, execute arbitrary\ncode with the privileges of the user running Thunderbird (CVE-2013-1682,\nCVE-2013-1684, CVE-2013-1685, CVE-2013-1686, CVE-2013-1687, CVE-2013-1690).\n\nIt was found that Thunderbird allowed data to be sent in the body of\nXMLHttpRequest (XHR) HEAD requests. In some cases this could allow\nattackers to conduct Cross-Site Request Forgery (CSRF) attacks\n(CVE-2013-1692).\n\nTiming differences in the way Thunderbird processed SVG image files could\nallow an attacker to read data across domains, potentially leading to\ninformation disclosure (CVE-2013-1693).\n\nTwo flaws were found in the way Thunderbird implemented some of its\ninternal structures (called wrappers). An attacker could use these flaws to\nbypass some restrictions placed on them. This could lead to unexpected\nbehavior or a potentially exploitable crash (CVE-2013-1694, CVE-2013-1697).\n","modified":"2026-04-16T04:44:28.706914857Z","published":"2013-06-26T18:45:58Z","upstream":["CVE-2013-1682","CVE-2013-1684","CVE-2013-1685","CVE-2013-1686","CVE-2013-1687","CVE-2013-1690","CVE-2013-1692","CVE-2013-1693","CVE-2013-1694","CVE-2013-1697"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2013-0189.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2013/mfsa2013-49.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2013/mfsa2013-50.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2013/mfsa2013-51.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2013/mfsa2013-53.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2013/mfsa2013-54.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2013/mfsa2013-55.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2013/mfsa2013-56.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2013/mfsa2013-59.html"},{"type":"WEB","url":"http://www.mozilla.org/security/known-vulnerabilities/firefoxESR.html"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2013-0981.html"},{"type":"WEB","url":"http://www.mozilla.org/security/known-vulnerabilities/thunderbirdESR.html"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2013-0982.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=10621"}],"affected":[{"package":{"name":"firefox","ecosystem":"Mageia:2","purl":"pkg:rpm/mageia/firefox?arch=source&distro=mageia-2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.0.7-1.mga2"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0189.json"}},{"package":{"name":"firefox-l10n","ecosystem":"Mageia:2","purl":"pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.0.7-1.mga2"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0189.json"}},{"package":{"name":"thunderbird","ecosystem":"Mageia:2","purl":"pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.0.7-1.mga2"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0189.json"}},{"package":{"name":"thunderbird-l10n","ecosystem":"Mageia:2","purl":"pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.0.7-1.mga2"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0189.json"}},{"package":{"name":"firefox","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/firefox?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.0.7-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0189.json"}},{"package":{"name":"firefox-l10n","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.0.7-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0189.json"}},{"package":{"name":"thunderbird","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.0.7-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0189.json"}},{"package":{"name":"thunderbird-l10n","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.0.7-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0189.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}