PT-2014-1454 · Mozilla+3 · Firefox+4
Published
2014-04-29
·
Updated
2024-12-12
·
CVE-2014-1522
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 29.0
SeaMonkey versions prior to 2.26
Description
The issue is related to the
mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem, which allows remote attackers to execute arbitrary code or cause a denial of service, including out-of-bounds read, memory corruption, and application crash, via specially crafted content.Recommendations
For Mozilla Firefox versions prior to 29.0, update to version 29.0 or later to resolve the issue.
For SeaMonkey versions prior to 2.26, update to version 2.26 or later to resolve the issue.
As a temporary workaround, consider disabling the Web Audio subsystem until a patch is available.
Exploit
Fix
DoS
RCE
Out of bounds Read
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Firefox
Seamonkey
Suse
Ubuntu