CVE-2014-1578: Buffer Overflow
The gettile function in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly execute arbitrary code via WebM frames with invalid tile sizes that are improperly handled in buffering operations during video playback.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1578?
CVE-2014-1578 has a severity rating of medium as it can lead to application crashes and potential arbitrary code execution.
How do I fix CVE-2014-1578?
To fix CVE-2014-1578, you should update Mozilla Firefox and Thunderbird to the latest versions that have addressed this vulnerability.
What versions are affected by CVE-2014-1578?
CVE-2014-1578 affects Mozilla Firefox versions prior to 33.0, Firefox ESR versions before 31.2, and Thunderbird versions before 31.2.
What are the potential consequences of CVE-2014-1578?
The potential consequences of CVE-2014-1578 include a denial of service via application crash and possible execution of arbitrary code.
Is CVE-2014-1578 exploitable remotely?
Yes, CVE-2014-1578 can be exploited remotely through specially crafted WebM frames.