CVE-2014-1489: Medium severity Oracle Solaris vulnerability
Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 27.0
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1489?
CVE-2014-1489 is classified as a moderate severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2014-1489?
To resolve CVE-2014-1489, users should upgrade to Mozilla Firefox version 27.0 or later.
What is CVE-2014-1489 about?
CVE-2014-1489 involves inadequate access restrictions that allow attackers to manipulate the session restore feature.
Who is affected by CVE-2014-1489?
CVE-2014-1489 affects versions of Mozilla Firefox prior to 27.0.
Can CVE-2014-1489 be exploited remotely?
Yes, CVE-2014-1489 can be exploited by remote attackers through crafted web pages.