PT-2014-1464 · Mozilla+1 · Thunderbird+3
Published
2014-07-22
·
Updated
2024-10-21
·
CVE-2014-1551
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 31.0
Firefox ESR versions prior to 24.7
Thunderbird versions prior to 24.7
Description
The issue is related to a use-after-free vulnerability in the FontTableRec destructor, allowing remote attackers to execute arbitrary code via crafted use of fonts in MathML content. This leads to improper handling of a DirectWrite font-face object.
Recommendations
For Mozilla Firefox versions prior to 31.0, update to version 31.0 or later.
For Firefox ESR versions prior to 24.7, update to version 24.7 or later.
For Thunderbird versions prior to 24.7, update to version 24.7 or later.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox Esr
Firefox
Suse
Thunderbird