Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 69.0%; technical severity is CVSS 8.8.
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.
Who should care
- Teams operating Ubuntu Linux, Debian Linux, Firefox +13 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Ubuntu Linux, Debian Linux, Firefox +13 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Mozilla Security advisory Mfsa2013 53
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Advisory
- Mozilla Security advisory Mfsa2013 53Mozilla · Vendor sourceVerification pending ↗
- Debian Security advisory Dsa 2716Debian · Vendor sourceVerification pending ↗
- Debian Security advisory Dsa 2720Debian · Vendor sourceVerification pending ↗
- Mozilla Security advisory Show Bug.cgiMozilla · Vendor sourceVerification pending ↗
- Mozilla Security advisory Show Bug.cgiMozilla · Vendor sourceVerification pending ↗
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CWE
- CWE-119
- Affected versions
- Canonical Ubuntu Linux (Version 12.04 | Version 12.10 | Version 13.04); Debian Debian Linux (Version 7.0); Mozilla Firefox (End Excluding 22.0 | Start Including 17.0, End Excluding 17.0.7); Mozilla Firefox and Thunderbird; Mozilla Thunderbird (End Excluding 17.0.7); Mozilla Thunderbird Esr (Start Including 17.0, End Excluding 17.0.7); Opensuse Opensuse (Version 11.4 | Version 12.2 | Version 12.3); Redhat Enterprise Linux Desktop (Version 5.0 | Version 6.0)
- Fixed versions
- Mozilla Firefox (Fixed from 22.0, 17.0.7); Mozilla Thunderbird (Fixed from 17.0.7); Mozilla Thunderbird Esr (Fixed from 17.0.7)
- Published
- 26 June 2013
- Attack vector
- Network
- Privileges required
- None
- User interaction
- Required
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 69.0%
- Signal calculated at 80
External references
- Red Hat Third-party advisory RHSA 2013 0981
- Red Hat Third-party advisory RHSA 2013 0982
- Ubuntu Third-party advisory USN-1890-1
- Ubuntu Third-party advisory USN-1891-1
- CISA Government advisory CVE-2013-1690
- Lists Opensuse Third-party advisory Msg00003
- Lists Opensuse Third-party advisory Msg00004
- Lists Opensuse Third-party advisory Msg00005
- Lists Opensuse Third-party advisory Msg00006
- Lists Opensuse Third-party advisory Msg00010
- Lists Opensuse Third-party advisory Msg00011
- Securityfocus Third-party advisory