First published: Thu Dec 11 2014(Updated: )
Mozilla Firefox before 34.0 and SeaMonkey before 2.31 provide stylesheets with an incorrect primary namespace, which allows remote attackers to bypass intended access restrictions via an XBL binding.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <=33.0 | |
Mozilla SeaMonkey | <=2.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1589 is considered a moderate severity vulnerability that allows remote attackers to bypass access restrictions.
To fix CVE-2014-1589, users should update Mozilla Firefox to version 34.0 or later and SeaMonkey to version 2.31 or later.
CVE-2014-1589 affects users of Mozilla Firefox versions prior to 34.0 and SeaMonkey versions prior to 2.31.
CVE-2014-1589 is an XML-based vulnerability that allows for the bypass of intended access restrictions through XBL binding.
Yes, CVE-2014-1589 can be exploited by remote attackers to compromise system security.