First published: Wed Jul 23 2014(Updated: )
Mozilla Firefox and Thunderbird could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error in the PK11_ImportCert() function when adding NSSCertificate structures. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 | |
Mozilla Firefox | <=30.0 | |
Mozilla Firefox | =24.0 | |
Mozilla Firefox | =24.1.0 | |
Mozilla Firefox | =24.1.1 | |
Mozilla Firefox ESR | =24.0.1 | |
Mozilla Firefox ESR | =24.0.2 | |
Mozilla Firefox ESR | =24.2 | |
Mozilla Firefox ESR | =24.3 | |
Mozilla Firefox ESR | =24.4 | |
Mozilla Firefox ESR | =24.5 | |
Mozilla Firefox ESR | =24.6 | |
Mozilla NSS ESR | =3.2 | |
Mozilla NSS ESR | =3.2.1 | |
Mozilla NSS ESR | =3.3 | |
Mozilla NSS ESR | =3.3.1 | |
Mozilla NSS ESR | =3.3.2 | |
Mozilla NSS ESR | =3.4 | |
Mozilla NSS ESR | =3.4.1 | |
Mozilla NSS ESR | =3.4.2 | |
Mozilla NSS ESR | =3.5 | |
Mozilla NSS ESR | =3.6 | |
Mozilla NSS ESR | =3.6.1 | |
Mozilla NSS ESR | =3.7 | |
Mozilla NSS ESR | =3.7.1 | |
Mozilla NSS ESR | =3.7.2 | |
Mozilla NSS ESR | =3.7.3 | |
Mozilla NSS ESR | =3.7.5 | |
Mozilla NSS ESR | =3.7.7 | |
Mozilla NSS ESR | =3.8 | |
Mozilla NSS ESR | =3.9 | |
Mozilla NSS ESR | =3.11.2 | |
Mozilla NSS ESR | =3.11.3 | |
Mozilla NSS ESR | =3.11.4 | |
Mozilla NSS ESR | =3.11.5 | |
Mozilla NSS ESR | =3.12 | |
Mozilla NSS ESR | =3.12.1 | |
Mozilla NSS ESR | =3.12.2 | |
Mozilla NSS ESR | =3.12.3 | |
Mozilla NSS ESR | =3.12.3.1 | |
Mozilla NSS ESR | =3.12.3.2 | |
Mozilla NSS ESR | =3.12.4 | |
Mozilla NSS ESR | =3.12.5 | |
Mozilla NSS ESR | =3.12.6 | |
Mozilla NSS ESR | =3.12.7 | |
Mozilla NSS ESR | =3.12.8 | |
Mozilla NSS ESR | =3.12.9 | |
Mozilla NSS ESR | =3.12.10 | |
Mozilla NSS ESR | =3.12.11 | |
Mozilla NSS ESR | =3.14 | |
Mozilla NSS ESR | =3.14.1 | |
Mozilla NSS ESR | =3.14.2 | |
Mozilla NSS ESR | =3.14.3 | |
Mozilla NSS ESR | =3.14.4 | |
Mozilla NSS ESR | =3.14.5 | |
Mozilla NSS ESR | =3.15 | |
Mozilla NSS ESR | =3.15.1 | |
Mozilla NSS ESR | =3.15.2 | |
Mozilla NSS ESR | =3.15.3 | |
Mozilla NSS ESR | =3.15.3.1 | |
Mozilla NSS ESR | =3.15.4 | |
Mozilla NSS ESR | =3.15.5 | |
Mozilla NSS ESR | =3.16 | |
Mozilla Thunderbird | <=24.6 | |
Mozilla Thunderbird | =24.0 | |
Mozilla Thunderbird | =24.0.1 | |
Mozilla Thunderbird | =24.1 | |
Mozilla Thunderbird | =24.1.1 | |
Mozilla Thunderbird | =24.2 | |
Mozilla Thunderbird | =24.3 | |
Mozilla Thunderbird | =24.4 | |
Mozilla Thunderbird | =24.5 | |
Mozilla Firefox ESR | =24.0 | |
Mozilla Firefox ESR | =24.1.0 | |
Mozilla Firefox ESR | =24.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1544 has a high severity rating due to its potential for remote code execution.
To fix CVE-2014-1544, users should update to the latest version of affected software, such as Mozilla Firefox, Thunderbird, or IBM Cognos Analytics.
Affected versions of Mozilla Firefox include versions up to 30.0, and affected versions of Thunderbird include versions up to 24.6.
Yes, CVE-2014-1544 can still impact systems that use vulnerable versions of IBM Cognos Analytics or other affected software.
CVE-2014-1544 is a use-after-free vulnerability that can lead to arbitrary code execution.