CVE-2014-1482

RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect write operations) via crafted image data, as demonstrated by Goo Create.
References
Link Resource
http://www.mozilla.org/security/announce/2014/mfsa2014-04.html Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=943803 Exploit Issue Tracking Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2014-0132.html Third Party Advisory
https://8pecxstudios.com/?page_id=44080 Broken Link
http://rhn.redhat.com/errata/RHSA-2014-0133.html Third Party Advisory
http://secunia.com/advisories/56706 Broken Link
http://www.ubuntu.com/usn/USN-2102-1 Third Party Advisory
http://www.debian.org/security/2014/dsa-2858 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html Mailing List Third Party Advisory
http://www.ubuntu.com/usn/USN-2119-1 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html Mailing List Third Party Advisory
http://www.ubuntu.com/usn/USN-2102-2 Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html Mailing List Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html Mailing List Third Party Advisory
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html Third Party Advisory
https://security.gentoo.org/glsa/201504-01 Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/90894 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1029721 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1029720 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1029717 Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/65328 Third Party Advisory VDB Entry
http://secunia.com/advisories/56922 Broken Link
http://secunia.com/advisories/56888 Broken Link
http://secunia.com/advisories/56858 Broken Link
http://secunia.com/advisories/56787 Broken Link
http://secunia.com/advisories/56767 Broken Link
http://secunia.com/advisories/56763 Broken Link
http://secunia.com/advisories/56761 Broken Link
http://osvdb.org/102868 Broken Link
http://download.novell.com/Download?buildid=Y2fux-JW1Qc Broken Link
http://download.novell.com/Download?buildid=VYQsgaFpQ2k Broken Link
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:6.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:6.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:6.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*

Configuration 6 (hide)

OR cpe:2.3:a:suse:suse_linux_enterprise_software_development_kit:11.0:sp3:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp3:*:*:*:-:*:*
cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp3:*:*:*:vmware:*:*

Information

Published : 2014-02-05 21:44

Updated : 2020-08-11 06:33


NVD link : CVE-2014-1482

Mitre link : CVE-2014-1482


JSON object : View

CWE
CWE-787

Out-of-bounds Write

Advertisement

dedicated server usa

Products Affected

redhat

  • enterprise_linux_desktop
  • enterprise_linux_server_aus
  • enterprise_linux_workstation
  • enterprise_linux_server_tus
  • enterprise_linux_server_eus
  • enterprise_linux_server
  • enterprise_linux_eus

mozilla

  • firefox_esr
  • thunderbird
  • firefox
  • seamonkey

suse

  • suse_linux_enterprise_desktop
  • suse_linux_enterprise_software_development_kit
  • suse_linux_enterprise_server

fedoraproject

  • fedora

canonical

  • ubuntu_linux

debian

  • debian_linux

opensuse

  • opensuse