PT-2014-1485 · Mozilla+3 · Firefox+5

Publicado

2014-04-29

·

Atualizado

2024-12-12

·

CVE-2014-1528

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 28.0 SeaMonkey version 2.25
Description The issue allows remote attackers to execute arbitrary code or cause a denial of service by painting on a CANVAS element, resulting in an out-of-bounds write and application crash. This is due to a vulnerability in the sse2 composite src x888 8888 function in Pixman, as used in Cairo.
Recommendations For Mozilla Firefox version 28.0, update to a version that contains a fix for this issue. For SeaMonkey version 2.25, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting the use of the CANVAS element until a patch is available.

Exploit

Correção

DoS

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00451
BDU:2015-00676
CVE-2014-1528
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
USN-2185-1

Produtos afetados

Cairo
Firefox
Pixman
Seamonkey
Suse
Ubuntu