CVE-2013-1054
Publication date 7 April 2021
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the extension entirely.
Status
Package | Ubuntu Release | Status |
---|---|---|
unity-firefox-extension | ||
14.04 LTS trusty |
Fixed 3.0.0+14.04.20140416-0ubuntu1.14.04.1
|
|
Notes
Severity score breakdown
Parameter | Value |
---|---|
Base score | 6.5 · Medium |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |