Upstream information

CVE-2013-1695 at MITRE

Description

Mozilla Firefox before 22.0 does not properly implement certain DocShell inheritance behavior for the sandbox attribute of an IFRAME element, which allows remote attackers to bypass intended access restrictions via a FRAME element within an IFRAME element.

SUSE information

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.96
Vector AV:N/AC:L/Au:N/C:P/I:N/A:N
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
SUSE Bugzilla entry: 825935 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 12.3
  • MozillaFirefox >= 22.0-1.25.1
  • MozillaFirefox-branding-upstream >= 22.0-1.25.1
  • MozillaFirefox-buildsymbols >= 22.0-1.25.1
  • MozillaFirefox-debuginfo >= 22.0-1.25.1
  • MozillaFirefox-debugsource >= 22.0-1.25.1
  • MozillaFirefox-devel >= 22.0-1.25.1
  • MozillaFirefox-translations-common >= 22.0-1.25.1
  • MozillaFirefox-translations-other >= 22.0-1.25.1
  • mozilla-nspr >= 4.9.6-1.10.1
  • mozilla-nspr-32bit >= 4.9.6-1.10.1
  • mozilla-nspr-debuginfo >= 4.9.6-1.10.1
  • mozilla-nspr-debuginfo-32bit >= 4.9.6-1.10.1
  • mozilla-nspr-debugsource >= 4.9.6-1.10.1
  • mozilla-nspr-devel >= 4.9.6-1.10.1
  • seamonkey >= 2.19-1.12.1
  • seamonkey-debuginfo >= 2.19-1.12.1
  • seamonkey-debugsource >= 2.19-1.12.1
  • seamonkey-dom-inspector >= 2.19-1.12.1
  • seamonkey-irc >= 2.19-1.12.1
  • seamonkey-translations-common >= 2.19-1.12.1
  • seamonkey-translations-other >= 2.19-1.12.1
  • seamonkey-venkman >= 2.19-1.12.1
Patchnames:
openSUSE-2013-556
openSUSE-2013-574
openSUSE Evergreen 11.4
  • MozillaFirefox >= 22.0-79.1
  • MozillaFirefox-branding-upstream >= 22.0-79.1
  • MozillaFirefox-buildsymbols >= 22.0-79.1
  • MozillaFirefox-debuginfo >= 22.0-79.1
  • MozillaFirefox-debugsource >= 22.0-79.1
  • MozillaFirefox-devel >= 22.0-79.1
  • MozillaFirefox-translations-common >= 22.0-79.1
  • MozillaFirefox-translations-other >= 22.0-79.1
  • MozillaThunderbird >= 17.0.7-65.1
  • MozillaThunderbird-buildsymbols >= 17.0.7-65.1
  • MozillaThunderbird-debuginfo >= 17.0.7-65.1
  • MozillaThunderbird-debugsource >= 17.0.7-65.1
  • MozillaThunderbird-devel >= 17.0.7-65.1
  • MozillaThunderbird-devel-debuginfo >= 17.0.7-65.1
  • MozillaThunderbird-translations-common >= 17.0.7-65.1
  • MozillaThunderbird-translations-other >= 17.0.7-65.1
  • enigmail >= 1.5.1+17.0.7-65.1
  • enigmail-debuginfo >= 1.5.1+17.0.7-65.1
  • seamonkey >= 2.19-69.1
  • seamonkey-debuginfo >= 2.19-69.1
  • seamonkey-debugsource >= 2.19-69.1
  • seamonkey-dom-inspector >= 2.19-69.1
  • seamonkey-irc >= 2.19-69.1
  • seamonkey-translations-common >= 2.19-69.1
  • seamonkey-translations-other >= 2.19-69.1
  • seamonkey-venkman >= 2.19-69.1
Patchnames:
2013-101
2013-105