CVE-2014-1480: Medium severity openSUSE openSUSE vulnerability
The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a downloaded file, via a crafted web site.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 27.0 - Upgrade
Upgrade
SeaMonkeyto a version that resolves this vulnerability.Fixed in 2.24
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1480?
CVE-2014-1480 has a medium severity rating as it allows for clickjacking attacks that can lead to unauthorized file downloads.
How do I fix CVE-2014-1480?
To fix CVE-2014-1480, update Mozilla Firefox to version 27.0 or later, or update SeaMonkey to version 2.24 or later.
Which versions of Firefox are affected by CVE-2014-1480?
CVE-2014-1480 affects all versions of Mozilla Firefox prior to 27.0.
Which versions of SeaMonkey are impacted by CVE-2014-1480?
CVE-2014-1480 impacts all versions of SeaMonkey before version 2.24.
What type of attack can CVE-2014-1480 facilitate?
CVE-2014-1480 can facilitate clickjacking attacks, allowing attackers to trigger unintended downloads.