Updated software packages for Mozilla Firefox, Thunderbird, Seamonkey that fixes several recently discovered security issues is now available for nearly all operating systems and platforms.
You should upgrade your software immediately!
Patched and Secure Versions
If you are not using one of the versions below, you are vulnerable.
Firefox 18.0
Firefox ESR 10.0.12
Firefox ESR 17.0.2
Thunderbird 17.0.2
Thunderbird ESR 10.0.12
Thunderbird ESR 17.0.2
SeaMonkey 2.15
Related MFSAs
MFSA 2013-20
Mis-issued TURKTRUST certificates
MFSA 2013-19
Use-after-free in Javascript Proxy objects
MFSA 2013-18
Use-after-free in Vibrate
MFSA 2013-17
Use-after-free in ListenerManager
MFSA 2013-16
Use-after-free in serializeToStream
MFSA 2013-15
Privilege escalation through plugin objects
MFSA 2013-14
Chrome Object Wrapper (COW) bypass through changing prototype
MFSA 2013-13
Memory corruption in XBL with XML bindings containing SVG
MFSA 2013-12
Buffer overflow in Javascript string concatenation
MFSA 2013-11
Address space layout leaked in XBL objects
MFSA 2013-10
Event manipulation in plugin handler to bypass same-origin policy
MFSA 2013-09
Compartment mismatch with quickstubs returned values
MFSA 2013-08
AutoWrapperChanger fails to keep objects alive during garbage collection
MFSA 2013-07
Crash due to handling of SSL on threads
MFSA 2013-05
Use-after-free when displaying table with many columns and column groups
MFSA 2013-04
URL spoofing in addressbar during page loads
MFSA 2013-03
Buffer Overflow in Canvas
MFSA 2013-02
Use-after-free and buffer overflow issues found using Address Sanitizer
MFSA 2013-01
Miscellaneous memory safety hazards (rv:18.0/ rv:10.0.12 / rv:17.0.2)
MFSA 2012-98
Firefox installer DLL hijacking
Related CVEs:
91811 – CVE-2013-0769 Mozilla: Miscellaneous memory safety hazards (rv:10.0.12) (MFSA 2013-01)
891821 – CVE-2013-0762 CVE-2013-0766 CVE-2013-0767 Mozilla: Use-after-free & buffer overflow w/Address Sanitizer (MFSA 2013-02)
891824 – CVE-2013-0759 Mozilla: URL spoofing in addressbar during page loads (MFSA 2013-04)
891825 – CVE-2013-0744 Mozilla: Use-after-free when displaying table with many columns and column groups (MFSA 2013-05)
892142 – CVE-2013-0746 Mozilla: Compartment mismatch with quickstubs returned values (MFSA 2013-09)
892144 – CVE-2013-0748 Mozilla: Address space layout leaked in XBL objects (MFSA 2013-11)
892145 – CVE-2013-0750 Mozilla: Buffer overflow in Javascript string concatenation (MFSA 2013-12)
892148 – CVE-2013-0758 Mozilla: Chrome Object Wrapper (COW) bypass through plugin objects (MFSA 2013-15)
892149 – CVE-2013-0753 Mozilla: Use-after-free in serializeToStream (MFSA 2013-16)
892150 – CVE-2013-0754 Mozilla: Use-after-free in ListenerManager (MFSA 2013-17)
References:
http://www.mozilla.org/security/known-vulnerabilities/firefoxESR.html
https://rhn.redhat.com/errata/RHSA-2013-0144.html
https://rhn.redhat.com/errata/RHSA-2013-0145.html