
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2013-1055 is a security vulnerability in the unity-firefox-extension package that could cause Firefox to crash. The vulnerability was discovered in 2013 and affected versions prior to 3.0.0+14.04.20140416-0ubuntu1.14.04.1. The issue occurs when the package drops a C callback that is still in use, which Firefox would then free, potentially leading to a crash (NVD).
The vulnerability involves a rate limit exploitation in libunity-webapps. The issue can be triggered by adding an action to the launcher and repeatedly updating it with new callbacks until the libunity-webapps rate limit is hit. When this occurs, the unity-firefox-extension stores a reference to the new (unused) callback while dropping its reference to the old (still in use) callback, which is then collected by the garbage collector. This leads to Firefox attempting to use freed memory, resulting in a crash (Launchpad Bug).
The primary impact of this vulnerability is a denial of service through application crashes. Additionally, since the freed memory could potentially be controlled by an attacker, there was a possibility that this vulnerability could be exploited to execute arbitrary code with the privileges of the user running Firefox (Launchpad Bug).
The vulnerability requires user interaction to be exploited. An attacker would need to trick a user into performing specific actions that would trigger the callback manipulation process. The vulnerability has a CVSS v3.1 Base Score of 4.3 (MEDIUM) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L (NVD).
The vulnerability was fixed in version 3.0.0+14.04.20140416-0ubuntu1.14.04.1 of unity-firefox-extension. The ultimate solution involved shipping an empty unity-firefox-extension package, effectively disabling the extension entirely and invalidating the attack against the libunity-webapps package (Ubuntu Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."