CVE-2014-1497

The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process heap memory, cause a denial of service (out-of-bounds read and application crash), or possibly have unspecified other impact via a crafted WAV file.

Published date
2014-03-19T10:55Z
Last modification date
2020-08-06T20:45Z
Assigner
security@mozilla.org
Problem type
CWE-125

Impact

CVSS v3 vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NameURLSourceTags
https://bugzilla.mozilla.org/show_bug.cgi?id=966311https://bugzilla.mozilla.org/show_bug.cgi?id=966311CONFIRMExploit, Issue Tracking, Vendor Advisory
http://www.mozilla.org/security/announce/2014/mfsa2014-17.htmlhttp://www.mozilla.org/security/announce/2014/mfsa2014-17.htmlCONFIRMVendor Advisory
DSA-2881http://www.debian.org/security/2014/dsa-2881DEBIANThird Party Advisory
RHSA-2014:0310http://rhn.redhat.com/errata/RHSA-2014-0310.htmlREDHATThird Party Advisory
RHSA-2014:0316http://rhn.redhat.com/errata/RHSA-2014-0316.htmlREDHATThird Party Advisory
openSUSE-SU-2014:0419http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.htmlSUSEMailing List, Third Party Advisory
SUSE-SU-2014:0418http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00016.htmlSUSEMailing List, Third Party Advisory
openSUSE-SU-2014:0448http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00022.htmlSUSEMailing List, Third Party Advisory
USN-2151-1http://www.ubuntu.com/usn/USN-2151-1UBUNTUThird Party Advisory
openSUSE-SU-2014:0584http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00016.htmlSUSEMailing List, Third Party Advisory
66423http://www.securityfocus.com/bid/66423BIDThird Party Advisory, VDB Entry
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlCONFIRMThird Party Advisory
GLSA-201504-01https://security.gentoo.org/glsa/201504-01GENTOOThird Party Advisory
DSA-2911http://www.debian.org/security/2014/dsa-2911DEBIANThird Party Advisory