First published: Wed Sep 03 2014(Updated: )
Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script that interacts with a CANVAS element associated with a malformed GIF image.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE Evergreen | =11.4 | |
openSUSE | =12.3 | |
openSUSE | =13.1 | |
Mozilla Firefox | <=31.1.0 | |
Mozilla Firefox | =30.0 | |
Mozilla Firefox | =31.0 | |
Mozilla Thunderbird | =31.0 | |
Mozilla Firefox ESR | =31.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1564 is considered a moderate severity vulnerability that can lead to sensitive information disclosure.
To fix CVE-2014-1564, update Mozilla Firefox and Thunderbird to versions 31.1 or later.
CVE-2014-1564 affects Mozilla Firefox versions up to 31.1, Firefox ESR 31.x up to 31.1, and Thunderbird 31.x up to 31.1, as well as specific versions of openSUSE.
Yes, CVE-2014-1564 can be exploited remotely through crafted web scripts that interact with a CANVAS element.
CVE-2014-1564 allows attackers to obtain sensitive information from process memory through exploitation of improperly initialized memory.