Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:MOZILLA:FF-COMPARTMENT

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Mozilla Firefox Web Browser Compartment Mismatch Re-attaching XBL-backed Nodes

Release Date

2013/11/11

Update Number

2318

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Mozilla Firefox Web Browser Compartment Mismatch Re-attaching XBL-backed Nodes


This signature detects attempts to exploit a known vulnerability against Mozilla Firefox Web Browser. A successful attack can lead to arbitrary code execution.

Extended Description

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly handle movement of XBL-backed nodes between documents, which allows remote attackers to execute arbitrary code or cause a denial of service (JavaScript compartment mismatch, or assertion failure and application exit) via a crafted web site.

Affected Products

  • mozilla firefox 19.0
  • mozilla firefox 19.0.1
  • mozilla firefox 19.0.2
  • mozilla firefox 20.0
  • mozilla firefox 20.0.1
  • mozilla firefox 21.0
  • mozilla firefox 22.0
  • mozilla firefox 23.0
  • mozilla firefox up to 23.0.1
  • mozilla firefox_esr 17.0
  • mozilla firefox_esr 17.0.1
  • mozilla firefox_esr 17.0.2
  • mozilla firefox_esr 17.0.3
  • mozilla firefox_esr 17.0.4
  • mozilla firefox_esr 17.0.5
  • mozilla firefox_esr 17.0.6
  • mozilla firefox_esr 17.0.7
  • mozilla firefox_esr 17.0.8
  • mozilla seamonkey 2.0.1
  • mozilla seamonkey 2.0.10
  • mozilla seamonkey 2.0.11
  • mozilla seamonkey 2.0.12
  • mozilla seamonkey 2.0.13
  • mozilla seamonkey 2.0.14
  • mozilla seamonkey 2.0.2
  • mozilla seamonkey 2.0.3
  • mozilla seamonkey 2.0.4
  • mozilla seamonkey 2.0.5
  • mozilla seamonkey 2.0.6
  • mozilla seamonkey 2.0.7
  • mozilla seamonkey 2.0.8
  • mozilla seamonkey 2.0.9
  • mozilla seamonkey 2.0 (alpha_1)
  • mozilla seamonkey 2.0 (alpha_2)
  • mozilla seamonkey 2.0 (alpha_3)
  • mozilla seamonkey 2.0 (beta_1)
  • mozilla seamonkey 2.0 (beta_2)
  • mozilla seamonkey 2.0 (rc1)
  • mozilla seamonkey 2.0 (rc2)
  • mozilla seamonkey 2.10.1
  • mozilla seamonkey 2.10 (beta1)
  • mozilla seamonkey 2.10 (beta2)
  • mozilla seamonkey 2.10 (beta3)
  • mozilla seamonkey 2.11 (beta1)
  • mozilla seamonkey 2.11 (beta2)
  • mozilla seamonkey 2.11 (beta3)
  • mozilla seamonkey 2.11 (beta4)
  • mozilla seamonkey 2.11 (beta5)
  • mozilla seamonkey 2.11 (beta6)
  • mozilla seamonkey 2.12.1
  • mozilla seamonkey 2.12 (beta1)
  • mozilla seamonkey 2.12 (beta2)
  • mozilla seamonkey 2.12 (beta3)
  • mozilla seamonkey 2.12 (beta4)
  • mozilla seamonkey 2.12 (beta5)
  • mozilla seamonkey 2.12 (beta6)
  • mozilla seamonkey 2.13.1
  • mozilla seamonkey 2.13.2
  • mozilla seamonkey 2.13 (beta1)
  • mozilla seamonkey 2.13 (beta2)
  • mozilla seamonkey 2.13 (beta3)
  • mozilla seamonkey 2.13 (beta4)
  • mozilla seamonkey 2.13 (beta5)
  • mozilla seamonkey 2.13 (beta6)
  • mozilla seamonkey 2.14 (beta1)
  • mozilla seamonkey 2.14 (beta2)
  • mozilla seamonkey 2.14 (beta3)
  • mozilla seamonkey 2.14 (beta4)
  • mozilla seamonkey 2.14 (beta5)
  • mozilla seamonkey 2.15.1
  • mozilla seamonkey 2.15.2
  • mozilla seamonkey 2.15 (beta1)
  • mozilla seamonkey 2.15 (beta2)
  • mozilla seamonkey 2.15 (beta3)
  • mozilla seamonkey 2.15 (beta4)
  • mozilla seamonkey 2.15 (beta5)
  • mozilla seamonkey 2.15 (beta6)
  • mozilla seamonkey 2.16.1
  • mozilla seamonkey 2.16.2
  • mozilla seamonkey 2.16 (beta1)
  • mozilla seamonkey 2.16 (beta2)
  • mozilla seamonkey 2.16 (beta3)
  • mozilla seamonkey 2.16 (beta4)
  • mozilla seamonkey 2.16 (beta5)
  • mozilla seamonkey 2.17.1
  • mozilla seamonkey 2.17 (beta1)
  • mozilla seamonkey 2.17 (beta2)
  • mozilla seamonkey 2.17 (beta3)
  • mozilla seamonkey 2.17 (beta4)
  • mozilla seamonkey 2.18 (beta1)
  • mozilla seamonkey 2.18 (beta2)
  • mozilla seamonkey 2.18 (beta3)
  • mozilla seamonkey 2.18 (beta4)
  • mozilla seamonkey 2.19 (beta1)
  • mozilla seamonkey 2.19 (beta2)
  • mozilla seamonkey 2.1 (alpha1)
  • mozilla seamonkey 2.1 (alpha2)
  • mozilla seamonkey 2.1 (alpha3)
  • mozilla seamonkey 2.1 (beta1)
  • mozilla seamonkey 2.1 (beta2)
  • mozilla seamonkey 2.1 (beta3)
  • mozilla seamonkey 2.1 (rc1)
  • mozilla seamonkey 2.1 (rc2)
  • mozilla seamonkey up to 2.20 (beta1)
  • mozilla seamonkey up to 2.20 (beta2)
  • mozilla seamonkey up to 2.20 (beta3)
  • mozilla thunderbird 17.0
  • mozilla thunderbird 17.0.1
  • mozilla thunderbird 17.0.2
  • mozilla thunderbird 17.0.3
  • mozilla thunderbird 17.0.4
  • mozilla thunderbird 17.0.5
  • mozilla thunderbird 17.0.6
  • mozilla thunderbird 17.0.7
  • mozilla thunderbird 17.0.8
  • mozilla thunderbird up to 17.0.9
  • mozilla thunderbird_esr 17.0
  • mozilla thunderbird_esr 17.0.1
  • mozilla thunderbird_esr 17.0.2
  • mozilla thunderbird_esr 17.0.3
  • mozilla thunderbird_esr 17.0.4
  • mozilla thunderbird_esr 17.0.5
  • mozilla thunderbird_esr 17.0.6
  • mozilla thunderbird_esr 17.0.7
  • mozilla thunderbird_esr 17.0.8

References

  • CVE: CVE-2013-1730

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out