CVE-2014-1479: High severity Mozilla Firefox vulnerability
The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent certain cloning operations, which allows remote attackers to bypass intended restrictions on XUL content via vectors involving XBL content scopes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mozilla Firefox / Firefox ESR / Thunderbird / SeaMonkeyto a version that resolves this vulnerability.Fixed in 27.0 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 24.3 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 24.3 - Upgrade
Upgrade
Mozilla SeaMonkeyto a version that resolves this vulnerability.Fixed in 2.24
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1479?
CVE-2014-1479 is rated as a moderate severity vulnerability.
How do I fix CVE-2014-1479?
To mitigate CVE-2014-1479, update affected applications such as Mozilla Firefox to version 27.0 or later, and Thunderbird to version 24.3 or later.
What software is affected by CVE-2014-1479?
CVE-2014-1479 affects Mozilla Firefox versions prior to 27.0, Firefox ESR 24.x versions before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24.
What type of vulnerability is CVE-2014-1479?
CVE-2014-1479 is a vulnerability that allows remote attackers to bypass intended restrictions on XUL content.
Can CVE-2014-1479 be exploited remotely?
Yes, CVE-2014-1479 can be exploited by remote attackers through specific vectors.