Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.2.1.2013.32
Category:General
Title:Mozilla Firefox Security Advisory (MFSA2013-32) - Linux
Summary:This host is missing a security update for Mozilla Firefox.
Description:Summary:
This host is missing a security update for Mozilla Firefox.

Vulnerability Insight:
Privilege escalation through Mozilla Maintenance Service
Security researcher Frederic Hoguin discovered
that the Mozilla Maintenance Service on Windows was vulnerable to a buffer
overflow. This system is used to update software without invoking the User
Account Control (UAC) prompt. The Mozilla Maintenance Service is configured to
allow unprivileged users to start it with arbitrary arguments. By manipulating
the data passed in these arguments, an attacker can execute arbitrary code with
the system privileges used by the service. This issue requires local file system
access to be exploitable.

Affected Software/OS:
Firefox version(s) below 20.

Solution:
The vendor has released an update. Please see the reference(s) for more information.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-0799
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17155
SuSE Security Announcement: SUSE-SU-2013:0645 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.html
SuSE Security Announcement: SUSE-SU-2013:0850 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00019.html
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.