CVE-2013-5598
Summary
| CVE | CVE-2013-5598 |
|---|---|
| State | PUBLISHED |
| Assigner | mozilla |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-10-30 10:55:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:C/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 19.0 | All | All | All |
| Application | Mozilla | Firefox | 19.0.1 | All | All | All |
| Application | Mozilla | Firefox | 19.0.2 | All | All | All |
| Application | Mozilla | Firefox | 20.0 | All | All | All |
| Application | Mozilla | Firefox | 20.0.1 | All | All | All |
| Application | Mozilla | Firefox | 21.0 | All | All | All |
| Application | Mozilla | Firefox | 22.0 | All | All | All |
| Application | Mozilla | Firefox | 23.0 | All | All | All |
| Application | Mozilla | Firefox | 23.0.1 | All | All | All |
| Application | Mozilla | Firefox | 24.0 | All | All | All |
| Application | Mozilla | Firefox | 24.0.1 | All | All | All |
| Application | Mozilla | Firefox | 24.0.2 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Gentoo Security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| [security-announce] openSUSE-SU-2013:1633-1: important: Mozilla Suite: U | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| MFSA 2013-99: Security bypass of PDF.js checks using iframes | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| [security-announce] openSUSE-SU-2013:1634-1: important: Mozilla updates | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Access Denied | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.