First published: Thu Feb 06 2014(Updated: )
Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native getter methods across different JavaScript engines.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <27.0 | |
Mozilla Firefox ESR | >=24.0<24.3 | |
Mozilla SeaMonkey | <2.24 | |
Mozilla Thunderbird | <24.3 | |
Fedoraproject Fedora | =19 | |
Fedoraproject Fedora | =20 | |
SUSE Linux Enterprise Software Development Kit | =11.0-sp3 | |
openSUSE | =11.4 | |
openSUSE | =12.3 | |
openSUSE | =13.1 | |
SUSE Linux Enterprise Desktop | =11-sp3 | |
SUSE Linux Enterprise Server | =11-sp3 | |
SUSE Linux Enterprise Server | =11-sp3 | |
redhat enterprise Linux desktop | =5.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux eus | =6.5 | |
redhat enterprise Linux server | =5.0 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server aus | =6.5 | |
redhat enterprise Linux server eus | =6.5 | |
redhat enterprise Linux server tus | =6.5 | |
redhat enterprise Linux workstation | =5.0 | |
redhat enterprise Linux workstation | =6.0 | |
Debian GNU/Linux | =7.0 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =12.10 | |
Ubuntu Linux | =13.10 | |
Fedora | =19 | |
Fedora | =20 | |
Debian | =7.0 | |
Ubuntu | =12.04 | |
Ubuntu | =12.10 | |
Ubuntu | =13.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1481 has a severity rating of medium, as it allows remote attackers to bypass restrictions on window objects.
To fix CVE-2014-1481, users should update to the latest version of Mozilla Firefox, Firefox ESR, Thunderbird, or SeaMonkey as applicable.
CVE-2014-1481 affects Mozilla Firefox versions before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24.
Users of Mozilla Firefox, Firefox ESR, Thunderbird, and SeaMonkey prior to their respective patched versions are impacted by CVE-2014-1481.
CVE-2014-1481 is a security vulnerability that involves inconsistencies in native getter methods across different JavaScript engines.