CVE-2014-1557

CVSS v2.0 9.3 (High)
93% Progress
EPSS 1.74 % (88th)
1.74% Progress
Affected Products 5
Advisories 10

The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does not properly handle the discarding of image data during function execution, which allows remote attackers to execute arbitrary code by triggering prolonged image scaling, as demonstrated by scaling of a high-quality image.

Weaknesses
CWE-94
Improper Control of Generation of Code ('Code Injection')
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2014-07-23 11:12:43
(10 years ago)
Updated Date
2017-01-07 02:59:39
(7 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Oracle Solaris 11.3 cpe:2.3:o:oracle:solaris:11.3

Configuration #2

    CPE23 From Up To
  Mozilla Firefox 30.0 and prior versions cpe:2.3:a:mozilla:firefox <= 30.0
  Mozilla Firefox Esr 24.0 cpe:2.3:a:mozilla:firefox_esr:24.0
  Mozilla Firefox Esr 24.0.1 cpe:2.3:a:mozilla:firefox_esr:24.0.1
  Mozilla Firefox Esr 24.0.2 cpe:2.3:a:mozilla:firefox_esr:24.0.2
  Mozilla Firefox Esr 24.1.0 cpe:2.3:a:mozilla:firefox_esr:24.1.0
  Mozilla Firefox Esr 24.1.1 cpe:2.3:a:mozilla:firefox_esr:24.1.1
  Mozilla Firefox Esr 24.2 cpe:2.3:a:mozilla:firefox_esr:24.2
  Mozilla Firefox Esr 24.3 cpe:2.3:a:mozilla:firefox_esr:24.3
  Mozilla Firefox Esr 24.4 cpe:2.3:a:mozilla:firefox_esr:24.4
  Mozilla Firefox Esr 24.5 cpe:2.3:a:mozilla:firefox_esr:24.5
  Mozilla Firefox Esr 24.6 cpe:2.3:a:mozilla:firefox_esr:24.6
  Mozilla Thunderbird 24.6 and prior versions cpe:2.3:a:mozilla:thunderbird <= 24.6
  Mozilla Thunderbird 24.0 cpe:2.3:a:mozilla:thunderbird:24.0
  Mozilla Thunderbird 24.0.1 cpe:2.3:a:mozilla:thunderbird:24.0.1
  Mozilla Thunderbird 24.1 cpe:2.3:a:mozilla:thunderbird:24.1
  Mozilla Thunderbird 24.1.1 cpe:2.3:a:mozilla:thunderbird:24.1.1
  Mozilla Thunderbird 24.2 cpe:2.3:a:mozilla:thunderbird:24.2
  Mozilla Thunderbird 24.3 cpe:2.3:a:mozilla:thunderbird:24.3
  Mozilla Thunderbird 24.4 cpe:2.3:a:mozilla:thunderbird:24.4
  Mozilla Thunderbird 24.5 cpe:2.3:a:mozilla:thunderbird:24.5

Configuration #3

    CPE23 From Up To
  Debian Linux 6.0 cpe:2.3:o:debian:debian_linux:6.0
  Debian Linux 7.0 cpe:2.3:o:debian:debian_linux:7.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...