CVE-2014-1508: Critical severity Mozilla Firefox vulnerability
The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process memory, cause a denial of service (out-of-bounds read and application crash), or possibly bypass the Same Origin Policy via vectors involving MathML polygon rendering.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1508?
CVE-2014-1508 has a severity rating that suggests it can lead to a denial of service and information disclosure.
How do I fix CVE-2014-1508?
To fix CVE-2014-1508, users should update their Mozilla Firefox, Firefox ESR, Thunderbird, or SeaMonkey to the latest versions that address this vulnerability.
Which software is affected by CVE-2014-1508?
CVE-2014-1508 affects specific versions of Mozilla Firefox, Firefox ESR, Thunderbird, and SeaMonkey, along with several versions of Red Hat and Debian operating systems.
What types of attacks can CVE-2014-1508 facilitate?
CVE-2014-1508 can allow attackers to conduct out-of-bounds reads, leading to application crashes and potential information leakage.
Is there a workaround for CVE-2014-1508?
There are no known workarounds for CVE-2014-1508; the recommended action is to apply the security updates.