{
  "threat_severity" : "Critical",
  "public_date" : "2013-06-25T00:00:00Z",
  "bugzilla" : {
    "description" : "Mozilla: Miscellaneous memory safety hazards (rv:17.0.7) (MFSA 2013-49)",
    "id" : "977597",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=977597"
  },
  "cvss" : {
    "cvss_base_score" : "6.8",
    "cvss_scoring_vector" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
    "status" : "verified"
  },
  "details" : [ "Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors." ],
  "acknowledgement" : "Red Hat would like to thank Mozilla project for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2013-06-25T00:00:00Z",
    "advisory" : "RHSA-2013:0982",
    "cpe" : "cpe:/a:redhat:rhel_productivity:5",
    "package" : "thunderbird-0:17.0.7-1.el5_9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2013-06-25T00:00:00Z",
    "advisory" : "RHSA-2013:0981",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "firefox-0:17.0.7-1.el5_9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2013-06-25T00:00:00Z",
    "advisory" : "RHSA-2013:0981",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "xulrunner-0:17.0.7-1.el5_9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2013-06-25T00:00:00Z",
    "advisory" : "RHSA-2013:0981",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "firefox-0:17.0.7-1.el6_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2013-06-25T00:00:00Z",
    "advisory" : "RHSA-2013:0981",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "xulrunner-0:17.0.7-1.el6_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2013-06-25T00:00:00Z",
    "advisory" : "RHSA-2013:0982",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "thunderbird-0:17.0.7-1.el6_4"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Affected",
    "package_name" : "thunderbird",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2013-1682\nhttps://nvd.nist.gov/vuln/detail/CVE-2013-1682\nhttp://www.mozilla.org/security/announce/2013/mfsa2013-49.html" ],
  "name" : "CVE-2013-1682",
  "csaw" : false
}