Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:MOZILLA:READYSTATE-UAF

Severity

High

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

Mozilla Firefox Onreadystatechange Use After Free

Release Date

2013/08/09

Update Number

2289

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Mozilla Firefox Onreadystatechange Use After Free


This signature detects attempts to exploit a known vulnerability against Mozilla Firefox Web Browser. A successful attack can lead to arbitrary code execution.

Extended Description

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.

Affected Products

  • mozilla firefox 19.0
  • mozilla firefox 19.0.1
  • mozilla firefox 19.0.2
  • mozilla firefox 20.0
  • mozilla firefox 20.0.1
  • mozilla firefox up to 21.0
  • mozilla firefox_esr 17.0
  • mozilla firefox_esr 17.0.1
  • mozilla firefox_esr 17.0.2
  • mozilla firefox_esr 17.0.3
  • mozilla firefox_esr 17.0.4
  • mozilla firefox_esr 17.0.5
  • mozilla firefox_esr 17.0.6
  • mozilla thunderbird 17.0
  • mozilla thunderbird 17.0.1
  • mozilla thunderbird 17.0.2
  • mozilla thunderbird 17.0.3
  • mozilla thunderbird 17.0.4
  • mozilla thunderbird 17.0.5
  • mozilla thunderbird up to 17.0.6
  • mozilla thunderbird_esr 17.0
  • mozilla thunderbird_esr 17.0.1
  • mozilla thunderbird_esr 17.0.2
  • mozilla thunderbird_esr 17.0.3
  • mozilla thunderbird_esr 17.0.4
  • mozilla thunderbird_esr 17.0.5
  • mozilla thunderbird_esr 17.0.6

References

  • BugTraq: 60778
  • CVE: CVE-2013-1690

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out