PT-2014-1456 · Mozilla+3 · Firefox+4
Published
2014-04-29
·
Updated
2024-12-12
·
CVE-2014-1525
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 29.0
SeaMonkey versions prior to 2.26
Description
The issue exists in the
mozilla::dom::TextTrack::AddCue function due to incorrect garbage collection related to Text Track Manager variables. This allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and heap memory corruption) via a crafted VIDEO element in an HTML document.Recommendations
For Mozilla Firefox versions prior to 29.0, update to version 29.0 or later to resolve the issue.
For SeaMonkey versions prior to 2.26, update to version 2.26 or later to resolve the issue.
As a temporary workaround, consider disabling the
AddCue function in the TextTrack object until a patch is available.Exploit
Fix
DoS
RCE
Use After Free
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Firefox
Seamonkey
Suse
Ubuntu