CVE-2014-1485: High severity Mozilla Firefox vulnerability
The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 27.0 - Upgrade
Upgrade
SeaMonkeyto a version that resolves this vulnerability.Fixed in 2.24
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1485?
CVE-2014-1485 has a medium severity level due to its potential to allow remote code execution via malicious XSLT.
How do I fix CVE-2014-1485?
To fix CVE-2014-1485, upgrade to Mozilla Firefox 27.0 or later and Mozilla SeaMonkey 2.24 or later.
Which software versions are affected by CVE-2014-1485?
CVE-2014-1485 affects Mozilla Firefox versions before 27.0 and SeaMonkey versions before 2.24.
What are the potential consequences of CVE-2014-1485?
The consequences of CVE-2014-1485 could include unauthorized execution of arbitrary XSLT code, leading to data theft or system compromise.
Is CVE-2014-1485 a web-based vulnerability?
Yes, CVE-2014-1485 is a web-based vulnerability that can be exploited through malicious online content.