CVE-2014-1525: Use After Free
The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly perform garbage collection for Text Track Manager variables, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and heap memory corruption) via a crafted VIDEO element in an HTML document.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1525?
CVE-2014-1525 has a high severity rating, allowing remote attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2014-1525?
To fix CVE-2014-1525, upgrade Mozilla Firefox to version 29.0 or later, or SeaMonkey to version 2.26 or later.
Which software versions are affected by CVE-2014-1525?
CVE-2014-1525 affects Mozilla Firefox versions before 29.0 and SeaMonkey versions before 2.26, along with certain versions of Ubuntu and openSUSE.
What types of attacks can exploit CVE-2014-1525?
CVE-2014-1525 can be exploited to execute arbitrary code or lead to denial of service due to use-after-free and improper memory management.
Is there a workaround for CVE-2014-1525?
There are no specific workarounds for CVE-2014-1525; updating to the latest software version is the recommended action.