VulnerabilityModified
CVE-2013-1054
The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash.
MEDIUM 6.5EPSS 1.34%
Does this matter?
Lower severity and a low EPSS score (1.34%). Track it; it rarely justifies an emergency change on its own.
Description
The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the extension entirely.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 1.34% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-404
- Affected
- canonical/unity-firefox-extension · canonical/ubuntu linux
- Source
- security@ubuntu.com
References
- https://launchpad.net/bugs/1175661Exploit, Vendor Advisory
- https://ubuntu.com/USN-2743-3Vendor Advisory
- https://launchpad.net/bugs/1175661Exploit, Vendor Advisory
- https://ubuntu.com/USN-2743-3Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.