CVE-2014-1564: Medium severity evergreen ils vulnerability
Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script that interacts with a CANVAS element associated with a malformed GIF image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1564?
CVE-2014-1564 is considered a moderate severity vulnerability that can lead to sensitive information disclosure.
How do I fix CVE-2014-1564?
To fix CVE-2014-1564, update Mozilla Firefox and Thunderbird to versions 31.1 or later.
What software is affected by CVE-2014-1564?
CVE-2014-1564 affects Mozilla Firefox versions up to 31.1, Firefox ESR 31.x up to 31.1, and Thunderbird 31.x up to 31.1, as well as specific versions of openSUSE.
Can CVE-2014-1564 be exploited remotely?
Yes, CVE-2014-1564 can be exploited remotely through crafted web scripts that interact with a CANVAS element.
What types of attacks are associated with CVE-2014-1564?
CVE-2014-1564 allows attackers to obtain sensitive information from process memory through exploitation of improperly initialized memory.