{
  "schema_version": "1.7.0",
  "id": "MGASA-2013-0329",
  "published": "2013-11-20T20:16:49Z",
  "modified": "2013-11-20T20:16:43Z",
  "summary": "Updated iceape packages fix many vulnerabilities",
  "details": "Updated iceape packages fix security issues:\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before\n17.0.7, and Thunderbird ESR 17.x before 17.0.7 allow remote attackers to\ncause a denial of service (memory corruption and application crash) or\npossibly execute arbitrary code via unknown vectors. (CVE-2013-1682)\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox before 22.0 allow remote attackers to cause a denial of service\n(memory corruption and application crash) or possibly execute arbitrary\ncode via unknown vectors. (CVE-2013-1683)\n\nUse-after-free vulnerability in the\nmozilla::dom::HTMLMediaElement::LookupMediaElementURITable function in\nMozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird\nbefore 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote\nattackers to execute arbitrary code or cause a denial of service (heap\nmemory corruption) via a crafted web site. (CVE-2013-1684)\n\nUse-after-free vulnerability in the nsIDocument::GetRootElement function in\nMozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird\nbefore 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote\nattackers to execute arbitrary code or cause a denial of service (heap\nmemory corruption) via a crafted web site. (CVE-2013-1685)\n\nUse-after-free vulnerability in the mozilla::ResetDir function in Mozilla\nFirefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before\n17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to\nexecute arbitrary code or cause a denial of service (heap memory\ncorruption) via unspecified vectors. (CVE-2013-1686)\n\nThe System Only Wrapper (SOW) and Chrome Object Wrapper (COW)\nimplementations in Mozilla Firefox before 22.0, Firefox ESR 17.x before\n17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7\ndo not properly restrict XBL user-defined functions, which allows remote\nattackers to execute arbitrary JavaScript code with chrome privileges, or\nconduct cross-site scripting (XSS) attacks, via a crafted web site.\n(CVE-2013-1687)\n\nMozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird\nbefore 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly\nhandle onreadystatechange events in conjunction with page reloading, which\nallows remote attackers to cause a denial of service (application crash) or\npossibly execute arbitrary code via a crafted web site that triggers an\nattempt to execute data at an unmapped memory location. (CVE-2013-1690)\n\nMozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird\nbefore 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not prevent the\ninclusion of body data in an XMLHttpRequest HEAD request, which makes it\neasier for remote attackers to conduct cross-site request forgery (CSRF)\nattacks via a crafted web site. (CVE-2013-1692)\n\nThe SVG filter implementation in Mozilla Firefox before 22.0, Firefox ESR\n17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x\nbefore 17.0.7 allows remote attackers to read pixel values, and possibly\nbypass the Same Origin Policy and read text from a different domain, by\nobserving timing differences in execution of filter code. (CVE-2013-1693)\n\nThe PreserveWrapper implementation in Mozilla Firefox before 22.0, Firefox\nESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x\nbefore 17.0.7 does not properly handle the lack of a wrapper, which allows\nremote attackers to cause a denial of service (application crash) or\npossibly execute arbitrary code by leveraging unintended clearing of the\nwrapper cache's preserved-wrapper flag. (CVE-2013-1694)\n\nMozilla Firefox before 22.0 does not properly implement certain DocShell\ninheritance behavior for the sandbox attribute of an IFRAME element, which\nallows remote attackers to bypass intended access restrictions via a FRAME\nelement within an IFRAME element. (CVE-2013-1695)\n\nMozilla Firefox before 22.0 does not properly enforce the X-Frame-Options\nprotection mechanism, which allows remote attackers to conduct clickjacking\nattacks via a crafted web site that uses the HTTP server push feature with\nmultipart responses. (CVE-2013-1696)\n\nThe XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR\n17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x\nbefore 17.0.7 does not properly restrict use of DefaultValue for method\ncalls, which allows remote attackers to execute arbitrary JavaScript code\nwith chrome privileges via a crafted web site that triggers use of a\nuser-defined (1) toString or (2) valueOf method. (CVE-2013-1697)\n\nThe Internationalized Domain Name (IDN) display algorithm in Mozilla\nFirefox before 22.0 does not properly handle the .com, .name, and .net\ntop-level domains, which allows remote attackers to spoof the address bar\nvia unspecified homograph characters. (CVE-2013-1699)\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before\n17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allow\nremote attackers to cause a denial of service (memory corruption and\napplication crash) or possibly execute arbitrary code via unknown vectors.\n(CVE-2013-1701)\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to\ncause a denial of service (memory corruption and application crash) or\npossibly execute arbitrary code via unknown vectors. (CVE-2013-1702)\n\nUse-after-free vulnerability in the nsINode::GetParentNode function in\nMozilla Firefox before 23.0 and SeaMonkey before 2.20 allows remote\nattackers to execute arbitrary code or cause a denial of service (heap\nmemory corruption and application crash) via vectors involving a DOM\nmodification at the time of a SetBody mutation event. (CVE-2013-1704)\n\nHeap-based buffer underflow in the cryptojs_interpret_key_gen_type function\nin Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allows remote\nattackers to execute arbitrary code or cause a denial of service\n(application crash) via a crafted Certificate Request Message Format (CRMF)\nrequest. (CVE-2013-1705)\n\nStack-based buffer overflow in maintenanceservice.exe in the Mozilla\nMaintenance Service in Mozilla Firefox before 23.0, Firefox ESR 17.x before\n17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8\nallows local users to gain privileges via a long pathname on the command\nline. (CVE-2013-1706)\n\nStack-based buffer overflow in Mozilla Updater in Mozilla Firefox before\n23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and\nThunderbird ESR 17.x before 17.0.8 allows local users to gain privileges\nvia a long pathname on the command line to the Mozilla Maintenance Service.\n(CVE-2013-1707)\n\nMozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote\nattackers to cause a denial of service (application crash) via a crafted\nWAV file that is not properly handled by the nsCString::CharAt function.\n(CVE-2013-1708)\n\nMozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird\nbefore 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before\n2.20 do not properly handle the interaction between FRAME elements and\nhistory, which allows remote attackers to conduct cross-site scripting\n(XSS) attacks via vectors involving spoofing a relative location in a\npreviously visited document. (CVE-2013-1709)\n\nThe crypto.generateCRMFRequest function in Mozilla Firefox before 23.0,\nFirefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR\n17.x before 17.0.8, and SeaMonkey before 2.20 allows remote attackers to\nexecute arbitrary JavaScript code or conduct cross-site scripting (XSS)\nattacks via vectors related to Certificate Request Message Format (CRMF)\nrequest generation. (CVE-2013-1710)\n\nThe XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey\nbefore 2.20 does not properly address the possibility of an XBL scope\nbypass resulting from non-native arguments in XBL function calls, which\nmakes it easier for remote attackers to conduct cross-site scripting (XSS)\nattacks by leveraging access to an unprivileged object. (CVE-2013-1711)\n\nMozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird\nbefore 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before\n2.20 use an incorrect URI within unspecified comparisons during enforcement\nof the Same Origin Policy, which allows remote attackers to conduct\ncross-site scripting (XSS) attacks or install arbitrary add-ons via a\ncrafted web site. (CVE-2013-1713)\n\nThe Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR\n17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before\n17.0.8, and SeaMonkey before 2.20 does not properly restrict XMLHttpRequest\ncalls, which allows remote attackers to bypass the Same Origin Policy and\nconduct cross-site scripting (XSS) attacks via unspecified vectors.\n(CVE-2013-1714)\n\nMozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird\nbefore 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before\n2.20 do not properly restrict local-filesystem access by Java applets,\nwhich allows user-assisted remote attackers to read arbitrary files by\nleveraging a download to a fixed pathname or other predictable pathname.\n(CVE-2013-1717)\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before\n24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allow\nremote attackers to cause a denial of service (memory corruption and\napplication crash) or possibly execute arbitrary code via unknown vectors.\n(CVE-2013-1718)\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21\nallow remote attackers to cause a denial of service (memory corruption and\napplication crash) or possibly execute arbitrary code via unknown vectors.\n(CVE-2013-1719)\n\nThe nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree\nBuilder in Mozilla Firefox before 24.0, Thunderbird before 24.0, and\nSeaMonkey before 2.21 does not properly maintain the state of the\ninsertion-mode stack for template elements, which allows remote attackers\nto execute arbitrary code or cause a denial of service (heap-based buffer\nover-read) by triggering use of this stack in its empty state.\n(CVE-2013-1720)\n\nInteger overflow in the drawLineLoop function in the libGLESv2 library in\nAlmost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox\nbefore 24.0 and SeaMonkey before 2.21, allows remote attackers to execute\narbitrary code via a crafted web site. (CVE-2013-1721)\n\nUse-after-free vulnerability in the nsAnimationManager::BuildAnimations\nfunction in the Animation Manager in Mozilla Firefox before 24.0, Firefox\nESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x\nbefore 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute\narbitrary code or cause a denial of service (heap memory corruption) via\nvectors involving stylesheet cloning. (CVE-2013-1722)\n\nThe NativeKey widget in Mozilla Firefox before 24.0, Thunderbird before\n24.0, and SeaMonkey before 2.21 processes key messages after destruction by\na dispatched event listener, which allows remote attackers to cause a\ndenial of service (application crash) by leveraging incorrect event usage\nafter widget-memory reallocation. (CVE-2013-1723)\n\nUse-after-free vulnerability in the\nmozilla::dom::HTMLFormElement::IsDefaultSubmitElement function in Mozilla\nFirefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21\nallows remote attackers to execute arbitrary code or cause a denial of\nservice (heap memory corruption) via vectors involving a destroyed SELECT\nelement. (CVE-2013-1724)\n\nMozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird\nbefore 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21\ndo not ensure that initialization occurs for JavaScript objects with\ncompartments, which allows remote attackers to execute arbitrary code by\nleveraging incorrect scope handling. (CVE-2013-1725)\n\nThe IonMonkey JavaScript engine in Mozilla Firefox before 24.0, Thunderbird\nbefore 24.0, and SeaMonkey before 2.21, when Valgrind mode is used, does\nnot properly initialize memory, which makes it easier for remote attackers\nto obtain sensitive information via unspecified vectors. (CVE-2013-1728)\n\nMozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird\nbefore 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21\ndo not properly handle movement of XBL-backed nodes between documents,\nwhich allows remote attackers to execute arbitrary code or cause a denial\nof service (JavaScript compartment mismatch, or assertion failure and\napplication exit) via a crafted web site. (CVE-2013-1730)\n\nBuffer overflow in the nsFloatManager::GetFlowArea function in Mozilla\nFirefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before\n24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows\nremote attackers to execute arbitrary code via crafted use of lists and\nfloats within a multi-column layout. (CVE-2013-1732)\n\nUse-after-free vulnerability in the mozilla::layout::ScrollbarActivity\nfunction in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9,\nThunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey\nbefore 2.21 allows remote attackers to execute arbitrary code via vectors\nrelated to image-document scrolling. (CVE-2013-1735)\n\nThe nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 24.0,\nFirefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR\n17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to\nexecute arbitrary code or cause a denial of service (memory corruption) via\nvectors related to improperly establishing parent-child relationships of\nrange-request nodes. (CVE-2013-1736)\n\nMozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird\nbefore 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21\ndo not properly identify the \"this\" object during use of user-defined\ngetter methods on DOM proxies, which might allow remote attackers to bypass\nintended access restrictions via vectors involving an expando object.\n(CVE-2013-1737)\n\nUse-after-free vulnerability in the JS_GetGlobalForScopeChain function in\nMozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before\n2.21 allows remote attackers to execute arbitrary code by leveraging\nincorrect garbage collection in situations involving default compartments\nand frame-chain restoration. (CVE-2013-1738)\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox before 25.0 allow remote attackers to cause a denial of service\n(memory corruption and application crash) or possibly execute arbitrary\ncode via unknown vectors. (CVE-2013-5592)\n\nUnspecified vulnerability in the browser engine in Mozilla Firefox before\n25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey\nbefore 2.22 allows remote attackers to cause a denial of service (memory\ncorruption and application crash) or possibly execute arbitrary code via\nunknown vectors. (CVE-2013-5591)\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1,\nThunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey\nbefore 2.22 allow remote attackers to cause a denial of service (memory\ncorruption and application crash) or possibly execute arbitrary code via\nunknown vectors. (CVE-2013-5590)\n\nThe SELECT element implementation in Mozilla Firefox before 25.0, Firefox\nESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22\ndoes not properly restrict the nature or placement of HTML within a\ndropdown menu, which allows remote attackers to spoof the address bar or\nconduct clickjacking attacks via vectors that trigger navigation off of a\npage containing this element. (CVE-2013-5593)\n\nThe txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla\nFirefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1,\nThunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey\nbefore 2.22 does not properly initialize data, which allows remote\nattackers to execute arbitrary code or cause a denial of service\n(stack-based buffer overflow and application crash) via crafted documents.\n(CVE-2013-5604)\n\nThe JavaScript engine in Mozilla Firefox before 25.0, Firefox ESR 17.x\nbefore 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird\nESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly\nallocate memory for unspecified functions, which allows remote attackers to\nconduct buffer overflow attacks via a crafted web page. (CVE-2013-5595)\n\nThe cycle collection (CC) implementation in Mozilla Firefox before 25.0,\nFirefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before\n2.22 does not properly determine the thread for release of an image object,\nwhich allows remote attackers to execute arbitrary code or cause a denial\nof service (race condition and application crash) via a large HTML document\ncontaining IMG elements, as demonstrated by the Never-Ending Reddit on\nreddit.com. (CVE-2013-5596)\n\nUse-after-free vulnerability in the nsDocLoader::doStopDocumentLoad\nfunction in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10\nand 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before\n17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute\narbitrary code or cause a denial of service (heap memory corruption) via\nvectors involving a state-change event during an update of the offline\ncache. (CVE-2013-5597)\n\nUse-after-free vulnerability in the nsIPresShell::GetPresContext function\nin the PresShell (aka presentation shell) implementation in Mozilla Firefox\nbefore 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1,\nThunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey\nbefore 2.22 allows remote attackers to execute arbitrary code or cause a\ndenial of service (heap memory corruption and application crash) via\nvectors involving a CANVAS element, a mozTextStyle attribute, and an\nonresize event. (CVE-2013-5599)\n\nUse-after-free vulnerability in the\nnsIOService::NewChannelFromURIWithProxyFlags function in Mozilla Firefox\nbefore 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1,\nThunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey\nbefore 2.22 allows remote attackers to execute arbitrary code via vectors\ninvolving a blob: URL. (CVE-2013-5600)\n\nUse-after-free vulnerability in the nsEventListenerManager::SetEventHandler\nfunction in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10\nand 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before\n17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute\narbitrary code via vectors related to a memory allocation through the\ngarbage collection (GC) API. (CVE-2013-5601)\n\nThe Worker::SetEventListener function in the Web workers implementation in\nMozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x\nbefore 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10,\nand SeaMonkey before 2.22 allows remote attackers to execute arbitrary code\nor cause a denial of service (memory corruption) via vectors related to\ndirect proxies. (CVE-2013-5602)\n\nUse-after-free vulnerability in the\nnsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla\nFirefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1,\nand SeaMonkey before 2.22 allows remote attackers to execute arbitrary code\nor cause a denial of service (heap memory corruption) via vectors involving\nHTML document templates. (CVE-2013-5603)\n",
  "upstream": [
    "CVE-2013-1682",
    "CVE-2013-1683",
    "CVE-2013-1684",
    "CVE-2013-1685",
    "CVE-2013-1686",
    "CVE-2013-1687",
    "CVE-2013-1690",
    "CVE-2013-1692",
    "CVE-2013-1693",
    "CVE-2013-1694",
    "CVE-2013-1695",
    "CVE-2013-1696",
    "CVE-2013-1697",
    "CVE-2013-1699",
    "CVE-2013-1701",
    "CVE-2013-1702",
    "CVE-2013-1704",
    "CVE-2013-1705",
    "CVE-2013-1706",
    "CVE-2013-1707",
    "CVE-2013-1708",
    "CVE-2013-1709",
    "CVE-2013-1710",
    "CVE-2013-1711",
    "CVE-2013-1713",
    "CVE-2013-1714",
    "CVE-2013-1717",
    "CVE-2013-1718",
    "CVE-2013-1719",
    "CVE-2013-1720",
    "CVE-2013-1721",
    "CVE-2013-1722",
    "CVE-2013-1723",
    "CVE-2013-1724",
    "CVE-2013-1725",
    "CVE-2013-1728",
    "CVE-2013-1730",
    "CVE-2013-1732",
    "CVE-2013-1735",
    "CVE-2013-1736",
    "CVE-2013-1737",
    "CVE-2013-1738",
    "CVE-2013-5590",
    "CVE-2013-5591",
    "CVE-2013-5592",
    "CVE-2013-5593",
    "CVE-2013-5595",
    "CVE-2013-5596",
    "CVE-2013-5597",
    "CVE-2013-5599",
    "CVE-2013-5600",
    "CVE-2013-5601",
    "CVE-2013-5602",
    "CVE-2013-5603",
    "CVE-2013-5604"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2013-0329.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-49.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-50.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-51.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-53.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-54.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-55.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-56.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-57.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-58.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-59.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-61.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-63.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-64.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-65.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-66.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-67.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-68.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-69.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-70.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-72.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-73.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-75.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-76.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-77.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-78.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-79.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-80.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-81.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-82.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-85.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-88.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-89.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-90.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-91.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-92.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-93.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-94.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-95.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-96.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-97.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-98.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-100.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-101.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-102.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=10707"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:2",
        "name": "iceape",
        "purl": "pkg:rpm/mageia/iceape?arch=source&distro=mageia-2"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.22-1.mga2"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:3",
        "name": "iceape",
        "purl": "pkg:rpm/mageia/iceape?arch=source&distro=mageia-3"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.22-1.mga3"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
