CVE-2014-1538

HIGH

Description

Use-after-free vulnerability in the nsTextEditRules::CreateMozBR function in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

References

http://linux.oracle.com/errata/ELSA-2014-0741.html

http://linux.oracle.com/errata/ELSA-2014-0742.html

http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00019.html

http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00023.html

http://lists.opensuse.org/opensuse-updates/2014-06/msg00040.html

http://lists.opensuse.org/opensuse-updates/2014-07/msg00001.html

http://lists.opensuse.org/opensuse-updates/2014-07/msg00004.html

http://rhn.redhat.com/errata/RHSA-2014-0741.html

http://rhn.redhat.com/errata/RHSA-2014-0742.html

http://secunia.com/advisories/58984

http://secunia.com/advisories/59052

http://secunia.com/advisories/59149

http://secunia.com/advisories/59150

http://secunia.com/advisories/59165

http://secunia.com/advisories/59169

http://secunia.com/advisories/59170

http://secunia.com/advisories/59171

http://secunia.com/advisories/59229

http://secunia.com/advisories/59275

http://secunia.com/advisories/59328

http://secunia.com/advisories/59377

http://secunia.com/advisories/59387

http://secunia.com/advisories/59425

http://secunia.com/advisories/59486

http://secunia.com/advisories/59866

http://www.debian.org/security/2014/dsa-2955

http://www.debian.org/security/2014/dsa-2960

http://www.mozilla.org/security/announce/2014/mfsa2014-49.html

http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html

http://www.securityfocus.com/bid/67976

http://www.securitytracker.com/id/1030386

http://www.securitytracker.com/id/1030388

http://www.ubuntu.com/usn/USN-2243-1

http://www.ubuntu.com/usn/USN-2250-1

https://bugzilla.mozilla.org/show_bug.cgi?id=1005584

https://bugzilla.redhat.com/show_bug.cgi?id=1107421

https://security.gentoo.org/glsa/201504-01

Details

Source: MITRE

Published: 2014-06-11

Updated: 2017-12-28

Risk Information

CVSS v2.0

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH