PT-2014-1485 · Mozilla+3 · Firefox+5

Published

2014-04-29

·

Updated

2024-12-12

·

CVE-2014-1528

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 28.0 SeaMonkey version 2.25
Description The issue allows remote attackers to execute arbitrary code or cause a denial of service by painting on a CANVAS element, resulting in an out-of-bounds write and application crash. This is due to a vulnerability in the sse2 composite src x888 8888 function in Pixman, as used in Cairo.
Recommendations For Mozilla Firefox version 28.0, update to a version that contains a fix for this issue. For SeaMonkey version 2.25, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting the use of the CANVAS element until a patch is available.

Exploit

Fix

DoS

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00451
BDU:2015-00676
CVE-2014-1528
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
USN-2185-1

Affected Products

Cairo
Firefox
Pixman
Seamonkey
Suse
Ubuntu