PT-2021-2656 · Canonical · Unity-Firefox-Extension
Chris Coulson
+3
·
Published
2015-09-24
·
Updated
2021-04-19
·
CVE-2013-1054
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
unity-firefox-extension versions prior to 3.0.0+14.04.20140416-0ubuntu1.14.04.1
Description
The issue is related to the unity-firefox-extension package, which could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. The problem is also associated with resource release errors.
Recommendations
For versions prior to 3.0.0+14.04.20140416-0ubuntu1.14.04.1, update to version 3.0.0+14.04.20140416-0ubuntu1.14.04.1 or later, which ships an empty package and thus disables the extension entirely. As a temporary workaround, consider disabling the unity-firefox-extension to prevent potential crashes.
Exploit
Fix
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unity-Firefox-Extension