CVE-2013-1693
Summary
| CVE | CVE-2013-1693 |
|---|---|
| State | PUBLISHED |
| Assigner | mozilla |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-06-26 03:19:10 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The SVG filter implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to read pixel values, and possibly bypass the Same Origin Policy and read text from a different domain, by observing timing differences in execution of filter code. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 17.0 | All | All | All |
| Application | Mozilla | Firefox | 17.0.1 | All | All | All |
| Application | Mozilla | Firefox | 17.0.2 | All | All | All |
| Application | Mozilla | Firefox | 17.0.3 | All | All | All |
| Application | Mozilla | Firefox | 17.0.4 | All | All | All |
| Application | Mozilla | Firefox | 17.0.5 | All | All | All |
| Application | Mozilla | Firefox | 17.0.6 | All | All | All |
| Application | Mozilla | Firefox | 19.0 | All | All | All |
| Application | Mozilla | Firefox | 19.0.1 | All | All | All |
| Application | Mozilla | Firefox | 19.0.2 | All | All | All |
| Application | Mozilla | Firefox | 20.0 | All | All | All |
| Application | Mozilla | Firefox | 20.0.1 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Thunderbird | 17.0 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.1 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.3 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.4 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.5 | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.1 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.2 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.3 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.4 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.5 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.6 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-2720-1 icedove | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Debian -- Security Information -- DSA-2716-1 iceweasel | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [security-announce] SUSE-SU-2013:1153-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| [security-announce] openSUSE-SU-2013:1141-1: important: MozillaThunderbi | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2013:1143-1: important: xulrunner: 17.0. | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| 711043 – (CVE-2013-1693) SVG Filter Timing Attack | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| USN-1890-1: Firefox vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| MFSA 2013-55: SVG filters can lead to information disclosure | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| [security-announce] openSUSE-SU-2013:1142-1: important: MozillaFirefox: | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| USN-1891-1: Thunderbird vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| [security-announce] openSUSE-SU-2013:1140-1: important: regular updates | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Mozilla Firefox and Thunderbird CVE-2013-1693 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [security-announce] SUSE-SU-2013:1152-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.