HTTP: Mozilla Firefox Web Browser Compartment Mismatch Re-attaching XBL-backed Nodes

This signature detects attempts to exploit a known vulnerability against Mozilla Firefox Web Browser. A successful attack can lead to arbitrary code execution.

Extended Description

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly handle movement of XBL-backed nodes between documents, which allows remote attackers to execute arbitrary code or cause a denial of service (JavaScript compartment mismatch, or assertion failure and application exit) via a crafted web site.

Affected Products

Mozilla firefox

References

CVE: CVE-2013-1730

Short Name
HTTP:STC:MOZILLA:FF-COMPARTMENT
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Browser CVE-2013-1730 Compartment Firefox Mismatch Mozilla Nodes Re-attaching Web XBL-backed
Release Date
11/11/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3751
False Positive
Unknown
Vendors

Mozilla

CVSS Score

6.8

Found a potential security threat?