6.2
CVSSv2

CVE-2013-1726

Published: 18/09/2013 Updated: 19/09/2017
CVSS v2 Base Score: 6.2 | Impact Score: 10 | Exploitability Score: 1.9
VMScore: 552
Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Mozilla Updater in Mozilla Firefox prior to 24.0, Firefox ESR 17.x prior to 17.0.9, Thunderbird prior to 24.0, Thunderbird ESR 17.x prior to 17.0.9, and SeaMonkey prior to 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla thunderbird esr 17.0.7

mozilla thunderbird esr 17.0

mozilla thunderbird esr 17.0.8

mozilla thunderbird esr 17.0.4

mozilla thunderbird esr 17.0.3

mozilla thunderbird esr 17.0.2

mozilla thunderbird esr 17.0.1

mozilla thunderbird esr 17.0.6

mozilla thunderbird esr 17.0.5

mozilla thunderbird 17.0.5

mozilla thunderbird 17.0.6

mozilla thunderbird 17.0.1

mozilla thunderbird 17.0.2

mozilla thunderbird 17.0.3

mozilla thunderbird 17.0.4

mozilla thunderbird 17.0.7

mozilla thunderbird 17.0

mozilla thunderbird 17.0.8

mozilla thunderbird

mozilla firefox 19.0.2

mozilla firefox

mozilla firefox 23.0

mozilla firefox 19.0.1

mozilla firefox 19.0

mozilla firefox 22.0

mozilla firefox 21.0

mozilla firefox 20.0.1

mozilla firefox 20.0

mozilla firefox esr 17.0.3

mozilla firefox esr 17.0.2

mozilla firefox esr 17.0.8

mozilla firefox esr 17.0.1

mozilla firefox esr 17.0

mozilla firefox esr 17.0.7

mozilla firefox esr 17.0.6

mozilla firefox esr 17.0.5

mozilla firefox esr 17.0.4

mozilla seamonkey 2.14

mozilla seamonkey 2.13

mozilla seamonkey 2.12

mozilla seamonkey 2.11

mozilla seamonkey 2.10.1

mozilla seamonkey 2.1

mozilla seamonkey 2.0.7

mozilla seamonkey 2.0.6

mozilla seamonkey 2.0.12

mozilla seamonkey 2.0.11

mozilla seamonkey 2.0

mozilla seamonkey 2.19

mozilla seamonkey 2.17

mozilla seamonkey 2.16

mozilla seamonkey 2.15

mozilla seamonkey 2.13.2

mozilla seamonkey 2.13.1

mozilla seamonkey 2.12.1

mozilla seamonkey 2.10

mozilla seamonkey 2.0.5

mozilla seamonkey 2.0.4

mozilla seamonkey 2.0.10

mozilla seamonkey 2.0.1

mozilla seamonkey 2.18

mozilla seamonkey 2.0.3

mozilla seamonkey 2.0.2

mozilla seamonkey 2.20

mozilla seamonkey 2.16.2

mozilla seamonkey 2.16.1

mozilla seamonkey 2.15.2

mozilla seamonkey 2.15.1

mozilla seamonkey 2.0.9

mozilla seamonkey 2.0.8

mozilla seamonkey 2.0.14

mozilla seamonkey 2.0.13

mozilla seamonkey

mozilla seamonkey 2.17.1

Vendor Advisories

Mozilla Foundation Security Advisory 2013-83 Mozilla Updater does not lock MAR file after signature verification Announced September 17, 2013 Reporter Seb Patane Impact High Products Firefox, Firefox ESR, SeaMonkey, Thunderbi ...