PT-2014-1464 · Mozilla+1 · Thunderbird+3
CVE-2014-1551
·
Publicado
2014-07-22
·
Atualizado
2024-10-21
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 31.0
Firefox ESR versions prior to 24.7
Thunderbird versions prior to 24.7
Description
The issue is related to a use-after-free vulnerability in the FontTableRec destructor, allowing remote attackers to execute arbitrary code via crafted use of fonts in MathML content. This leads to improper handling of a DirectWrite font-face object.
Recommendations
For Mozilla Firefox versions prior to 31.0, update to version 31.0 or later.
For Firefox ESR versions prior to 24.7, update to version 24.7 or later.
For Thunderbird versions prior to 24.7, update to version 24.7 or later.
Correção
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Firefox Esr
Firefox
Suse
Thunderbird