First published: Wed Oct 15 2014(Updated: )
Mozilla Firefox before 33.0 does not properly initialize memory for GIF images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers a sequence of rendering operations for truncated GIF data within a CANVAS element.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <=32.0 | |
Mozilla Firefox | =30.0 | |
Mozilla Firefox | =31.0 | |
Mozilla Firefox | =31.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1580 is considered to have a medium severity level due to its potential to disclose sensitive information.
To fix CVE-2014-1580, users should upgrade Mozilla Firefox to version 33.0 or later.
CVE-2014-1580 affects Mozilla Firefox versions before 33.0, specifically 30.0 to 32.0 and certain 31.x versions.
Yes, CVE-2014-1580 can be exploited using specially crafted GIF images that can allow access to sensitive process memory.
Attackers can potentially obtain sensitive information from process memory via exploitation of CVE-2014-1580.