UBUNTU-CVE-2013-1055

Source
https://ubuntu.com/security/CVE-2013-1055
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-1055.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2013-1055
Upstream
  • CVE-2013-1055
Related
Published
2021-04-07T20:15:00Z
Modified
2026-02-04T04:19:30.568872Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVSS Calculator
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVSS Calculator
  • Ubuntu - low
Summary
[none]
Details

The unity-firefox-extension package could be tricked into dropping a C callback which was still in use, which Firefox would then free, causing Firefox to crash. This could be achieved by adding an action to the launcher and updating it with new callbacks until the libunity-webapps rate limit was hit. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 of unity-firefox-extension and in all versions of libunity-webapps by shipping an empty unity-firefox-extension package, thus disabling the extension entirely and invalidating the attack against the libunity-webapps package.

References

Affected packages

Ubuntu:14.04:LTS / unity-firefox-extension

Package

Name
unity-firefox-extension
Purl
pkg:deb/ubuntu/unity-firefox-extension@3.0.0+14.04.20140416-0ubuntu1.14.04.1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.0+14.04.20140416-0ubuntu1.14.04.1

Affected versions

2.*
2.4.8+13.10.20130920-0ubuntu1
3.*
3.0.0+14.04.20140130.1-0ubuntu1
3.0.0+14.04.20140205-0ubuntu1
3.0.0+14.04.20140220-0ubuntu1
3.0.0+14.04.20140411-0ubuntu1
3.0.0+14.04.20140416-0ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libufe-xidgetter0",
            "binary_version": "3.0.0+14.04.20140416-0ubuntu1.14.04.1"
        },
        {
            "binary_name": "xul-ext-unity",
            "binary_version": "3.0.0+14.04.20140416-0ubuntu1.14.04.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-1055.json"