SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-1054

The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash.

MEDIUM 6.5EPSS 1.34%

Does this matter?

Lower severity and a low EPSS score (1.34%). Track it; it rarely justifies an emergency change on its own.

Description

The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the extension entirely.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
1.34% probability · 70th percentile
CISA KEV
Not listed
Weakness
CWE-404
Affected
canonical/unity-firefox-extension · canonical/ubuntu linux
Source
security@ubuntu.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.