PT-2021-2656 · Canonical · Unity-Firefox-Extension

Chris Coulson

+3

·

Published

2015-09-24

·

Updated

2021-04-19

·

CVE-2013-1054

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions unity-firefox-extension versions prior to 3.0.0+14.04.20140416-0ubuntu1.14.04.1
Description The issue is related to the unity-firefox-extension package, which could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. The problem is also associated with resource release errors.
Recommendations For versions prior to 3.0.0+14.04.20140416-0ubuntu1.14.04.1, update to version 3.0.0+14.04.20140416-0ubuntu1.14.04.1 or later, which ships an empty package and thus disables the extension entirely. As a temporary workaround, consider disabling the unity-firefox-extension to prevent potential crashes.

Exploit

Fix

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02185
CVE-2013-1054
USN-2743-3

Affected Products

Unity-Firefox-Extension