Use-after-free vulnerability in the mozilla::dom::HTMLMediaElement::LookupMediaElementURITable function in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted web site.
CPE | Name | Operator | Version |
---|---|---|---|
firefox | eq | 19.0 | |
firefox | eq | 19.0.2 | |
firefox | eq | 20.0.1 | |
firefox | eq | 19.0.1 | |
firefox | eq | 20.0 | |
firefox | le | 21.0 | |
firefox_esr | eq | 17.0.5 | |
firefox_esr | eq | 17.0 | |
firefox_esr | eq | 17.0.1 | |
firefox_esr | eq | 17.0.6 |
lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html
lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html
lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html
lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html
lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html
lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html
rhn.redhat.com/errata/RHSA-2013-0981.html
rhn.redhat.com/errata/RHSA-2013-0982.html
www.debian.org/security/2013/dsa-2716
www.debian.org/security/2013/dsa-2720
www.mozilla.org/security/announce/2013/mfsa2013-50.html
www.securityfocus.com/bid/60766
www.ubuntu.com/usn/USN-1890-1
www.ubuntu.com/usn/USN-1891-1
bugzilla.mozilla.org/show_bug.cgi?id=865537
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16604