{"id":"MGASA-2014-0006","summary":"Updated firefox and thunderbird packages fix security vulnerabilities","details":"Several flaws were found in the processing of malformed web content. A web\npage containing malicious content could cause Firefox or Thunderbird to\nterminate unexpectedly or, potentially, execute arbitrary code with the\nprivileges of the user running Firefox or Thunderbird (CVE-2013-5609,\nCVE-2013-5616, CVE-2013-5618, CVE-2013-6671, CVE-2013-5613).\n\nIt was found that a subordinate Certificate Authority (CA) mis-issued an\nintermediate certificate, which could be used to conduct man-in-the-middle\nattacks. This update renders that particular intermediate certificate as\nuntrusted (MFSA 2013-117).\n\nThe rootcerts and nss packages have been updated to fix the MFSA 2013-117\nissue.  The thunderbird-lightning package has been updated to a version\nthat is compatible with the updated thunderbird.\n","modified":"2026-04-16T06:22:30.126761328Z","published":"2014-01-06T01:17:50Z","upstream":["CVE-2013-5609","CVE-2013-5613","CVE-2013-5616","CVE-2013-5618","CVE-2013-6671"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0006.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=11945"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2013/mfsa2013-104.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2013/mfsa2013-108.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2013/mfsa2013-109.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2013/mfsa2013-111.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2013/mfsa2013-114.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2013/mfsa2013-117.html"},{"type":"WEB","url":"http://www.mozilla.org/security/known-vulnerabilities/firefoxESR.html"},{"type":"WEB","url":"http://www.mozilla.org/security/known-vulnerabilities/thunderbird.html"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2013-1812.html"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2013-1823.html"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2013-1861.html"}],"affected":[{"package":{"name":"rootcerts","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/rootcerts?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20131204.00-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0006.json"}},{"package":{"name":"nss","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/nss?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.15.3.1-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0006.json"}},{"package":{"name":"firefox","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/firefox?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.2.0-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0006.json"}},{"package":{"name":"firefox-l10n","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.2.0-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0006.json"}},{"package":{"name":"thunderbird","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.2.0-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0006.json"}},{"package":{"name":"thunderbird-l10n","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.2.0-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0006.json"}},{"package":{"name":"thunderbird-lightning","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/thunderbird-lightning?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.4-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0006.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}