First published: Wed Jun 11 2014(Updated: )
Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code via vectors related to a crafted AudioBuffer channel count and sample rate.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE | =13.1 | |
openSUSE | =12.3 | |
Mozilla Firefox | <=29.0.1 | |
Oracle Solaris SPARC | =11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1542 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2014-1542, update Mozilla Firefox to version 30.0 or later.
CVE-2014-1542 can allow remote attackers to execute arbitrary code on affected systems, potentially leading to complete system compromise.
CVE-2014-1542 affects Mozilla Firefox versions up to and including 29.0.1, as well as certain versions of openSUSE and Oracle Solaris.
CVE-2014-1542 poses a higher risk in environments where Mozilla Firefox is used for untrusted web content, especially in versions prior to 30.0.