PT-2014-4220 · Mozilla+2 · Firefox+2

Published

2014-06-10

·

Updated

2024-12-12

·

CVE-2014-1543

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 30.0
Description The issue is related to multiple heap-based buffer overflows in the navigator.getGamepads function within the Gamepad API. This allows remote attackers to execute arbitrary code by utilizing non-contiguous axes with either a physical or virtual Gamepad device.
Recommendations For versions prior to 30.0, update to version 30.0 or later to resolve the issue. As a temporary workaround, consider disabling the navigator.getGamepads function until a patch is available. Restrict access to the Gamepad API to minimize the risk of exploitation. Avoid using non-contiguous axes with Gamepad devices in the affected API endpoint until the issue is resolved.

Exploit

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1978
CVE-2014-1543
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1

Affected Products

Alt Linux
Firefox
Suse