CVE-2014-1541

critical

Description

Use-after-free vulnerability in the RefreshDriverTimer::TickDriver function in the SMIL Animation Controller in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted web content.

References

http://linux.oracle.com/errata/ELSA-2014-0741.html

http://linux.oracle.com/errata/ELSA-2014-0742.html

http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00019.html

http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00023.html

http://lists.opensuse.org/opensuse-updates/2014-06/msg00040.html

http://lists.opensuse.org/opensuse-updates/2014-07/msg00001.html

http://lists.opensuse.org/opensuse-updates/2014-07/msg00004.html

http://rhn.redhat.com/errata/RHSA-2014-0741.html

http://rhn.redhat.com/errata/RHSA-2014-0742.html

https://bugzilla.mozilla.org/show_bug.cgi?id=1000185

http://secunia.com/advisories/58984

http://secunia.com/advisories/59052

http://secunia.com/advisories/59149

http://secunia.com/advisories/59150

http://secunia.com/advisories/59165

http://secunia.com/advisories/59169

http://secunia.com/advisories/59170

http://secunia.com/advisories/59171

http://secunia.com/advisories/59229

http://secunia.com/advisories/59275

http://secunia.com/advisories/59328

http://secunia.com/advisories/59377

http://secunia.com/advisories/59387

http://secunia.com/advisories/59425

http://secunia.com/advisories/59486

http://secunia.com/advisories/59866

https://security.gentoo.org/glsa/201504-01

http://www.debian.org/security/2014/dsa-2955

http://www.debian.org/security/2014/dsa-2960

http://www.mozilla.org/security/announce/2014/mfsa2014-52.html

http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html

http://www.securitytracker.com/id/1030386

http://www.securitytracker.com/id/1030388

http://www.ubuntu.com/usn/USN-2243-1

http://www.ubuntu.com/usn/USN-2250-1

Details

Source: Mitre, NVD

Published: 2014-06-11

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical