PT-2014-1464 · Mozilla+1 · Thunderbird+3

Published

2014-07-22

·

Updated

2024-10-21

·

CVE-2014-1551

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 31.0 Firefox ESR versions prior to 24.7 Thunderbird versions prior to 24.7
Description The issue is related to a use-after-free vulnerability in the FontTableRec destructor, allowing remote attackers to execute arbitrary code via crafted use of fonts in MathML content. This leads to improper handling of a DirectWrite font-face object.
Recommendations For Mozilla Firefox versions prior to 31.0, update to version 31.0 or later. For Firefox ESR versions prior to 24.7, update to version 24.7 or later. For Thunderbird versions prior to 24.7, update to version 24.7 or later.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2015-00429
BDU:2015-00459
BDU:2015-00699
CVE-2014-1551

Affected Products

Firefox Esr
Firefox
Suse
Thunderbird