Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2013.0320
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2013-0320)
Summary:The remote host is missing an update for the 'firefox, firefox-l10n, nspr, nss, rootcerts, sqlite3' package(s) announced via the MGASA-2013-0320 advisory.
Description:Summary:
The remote host is missing an update for the 'firefox, firefox-l10n, nspr, nss, rootcerts, sqlite3' package(s) announced via the MGASA-2013-0320 advisory.

Vulnerability Insight:
Updated firefox packages fix security vulnerabilities:

Mozilla Network Security Services (NSS) before 3.15.2 does not ensure
that data structures are initialized before read operations, which
allow remote attackers to cause a denial of service or possibly have
unspecified other impact via vectors that trigger a decryption failure
(CVE-2013-1739).

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to terminate
unexpectedly or, potentially, execute arbitrary code with the privileges of
the user running Firefox (CVE-2013-5590, CVE-2013-5597, CVE-2013-5599,
CVE-2013-5600, CVE-2013-5601, CVE-2013-5602).

It was found that the Firefox JavaScript engine incorrectly allocated
memory for certain functions. An attacker could combine this flaw with
other vulnerabilities to execute arbitrary code with the privileges of the
user running Firefox (CVE-2013-5595).

A flaw was found in the way Firefox handled certain Extensible Stylesheet
Language Transformations (XSLT) files. An attacker could combine this flaw
with other vulnerabilities to execute arbitrary code with the privileges of
the user running Firefox (CVE-2013-5604).

Additionally, the rootcerts, nspr, nss, and sqlite3 packages have been updated
to newer versions required by this update.

Affected Software/OS:
'firefox, firefox-l10n, nspr, nss, rootcerts, sqlite3' package(s) on Mageia 2, Mageia 3.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-1739
BugTraq ID: 62966
http://www.securityfocus.com/bid/62966
Bugtraq: 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/534161/100/0/threaded
Debian Security Information: DSA-2790 (Google Search)
http://www.debian.org/security/2013/dsa-2790
http://seclists.org/fulldisclosure/2014/Dec/23
http://security.gentoo.org/glsa/glsa-201406-19.xml
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19254
RedHat Security Advisories: RHSA-2013:1791
http://rhn.redhat.com/errata/RHSA-2013-1791.html
RedHat Security Advisories: RHSA-2013:1829
http://rhn.redhat.com/errata/RHSA-2013-1829.html
SuSE Security Announcement: SUSE-SU-2013:1678 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00014.html
SuSE Security Announcement: openSUSE-SU-2013:1539 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-10/msg00013.html
SuSE Security Announcement: openSUSE-SU-2013:1542 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-10/msg00016.html
http://www.ubuntu.com/usn/USN-2030-1
Common Vulnerability Exposure (CVE) ID: CVE-2013-5590
Debian Security Information: DSA-2788 (Google Search)
http://www.debian.org/security/2013/dsa-2788
Debian Security Information: DSA-2797 (Google Search)
http://www.debian.org/security/2013/dsa-2797
https://security.gentoo.org/glsa/201504-01
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19001
RedHat Security Advisories: RHSA-2013:1476
http://rhn.redhat.com/errata/RHSA-2013-1476.html
RedHat Security Advisories: RHSA-2013:1480
http://rhn.redhat.com/errata/RHSA-2013-1480.html
SuSE Security Announcement: openSUSE-SU-2013:1633 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00005.html
SuSE Security Announcement: openSUSE-SU-2013:1634 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00006.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-5595
BugTraq ID: 63421
http://www.securityfocus.com/bid/63421
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18694
Common Vulnerability Exposure (CVE) ID: CVE-2013-5597
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19277
Common Vulnerability Exposure (CVE) ID: CVE-2013-5599
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19315
Common Vulnerability Exposure (CVE) ID: CVE-2013-5600
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19172
Common Vulnerability Exposure (CVE) ID: CVE-2013-5601
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18495
Common Vulnerability Exposure (CVE) ID: CVE-2013-5602
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19293
Common Vulnerability Exposure (CVE) ID: CVE-2013-5604
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19091
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.