CVE-2013-0782

Heap-based buffer overflow in the nsSaveAsCharset::DoCharsetConversion function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code via unspecified vectors.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2013-02/msg00062.html Mailing List Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0271.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0272.html Third Party Advisory
http://www.debian.org/security/2013/dsa-2699 Third Party Advisory
http://www.mozilla.org/security/announce/2013/mfsa2013-28.html Vendor Advisory
http://www.ubuntu.com/usn/USN-1729-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-1729-2 Third Party Advisory
http://www.ubuntu.com/usn/USN-1748-1 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=827070 Issue Tracking Patch Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16906 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2013-02/msg00062.html Mailing List Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0271.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0272.html Third Party Advisory
http://www.debian.org/security/2013/dsa-2699 Third Party Advisory
http://www.mozilla.org/security/announce/2013/mfsa2013-28.html Vendor Advisory
http://www.ubuntu.com/usn/USN-1729-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-1729-2 Third Party Advisory
http://www.ubuntu.com/usn/USN-1748-1 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=827070 Issue Tracking Patch Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16906 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_aus:5.9:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:5.9:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:6.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*

History

No history.

Information

Published : 2013-02-19 23:55

Updated : 2025-04-11 00:51


NVD link : CVE-2013-0782

Mitre link : CVE-2013-0782

CVE.ORG link : CVE-2013-0782


JSON object : View

Products Affected

opensuse

  • opensuse

redhat

  • enterprise_linux_workstation
  • enterprise_linux_desktop
  • enterprise_linux_eus
  • enterprise_linux_aus
  • enterprise_linux_server

mozilla

  • thunderbird_esr
  • thunderbird
  • firefox
  • seamonkey

debian

  • debian_linux

canonical

  • ubuntu_linux
CWE
CWE-787

Out-of-bounds Write