CVE-2014-1496: Medium severity Mozilla Firefox vulnerability
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 28.0 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 24.4 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 24.4 - Upgrade
Upgrade
Mozilla SeaMonkeyto a version that resolves this vulnerability.Fixed in 2.25
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1496?
CVE-2014-1496 is considered to have a medium severity level allowing local users to gain privileges.
How do I fix CVE-2014-1496?
To fix CVE-2014-1496, update Mozilla Firefox to version 28.0 or later, and update Thunderbird, SeaMonkey, and Firefox ESR to their respective patched versions.
Who is affected by CVE-2014-1496?
CVE-2014-1496 affects users of Mozilla Firefox before version 28.0, Firefox ESR versions, Thunderbird before 24.4, and SeaMonkey before 2.25.
What type of vulnerability is CVE-2014-1496?
CVE-2014-1496 is a local privilege escalation vulnerability that can be exploited during the update process of affected software.
Is there a workaround for CVE-2014-1496?
There are no known effective workarounds for CVE-2014-1496, and the best course of action is to apply the necessary software updates.