[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Mozilla Products: Crash in Skia library when scaling high quality images - CVE-2014-1557 (Mac OS X)

ID: oval:org.secpod.oval:def:20632Date: (C)2014-07-28   (M)2023-12-07
Class: VULNERABILITYFamily: macos




The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does not properly handle the discarding of image data during function execution, which allows remote attackers to execute arbitrary code by triggering prolonged image scaling, as demonstrated by scaling of a high-quality image.

Platform:
Apple Mac OS 14
Apple Mac OS 13
Apple Mac OS 12
Apple Mac OS 11
Apple Mac OS X 10.15
Apple Mac OS X 10.14
Apple Mac OS X 10.13
Apple Mac OS X 10.11
Apple Mac OS X 10.12
Product:
Mozilla Thunderbird
Mozilla Firefox ESR
Mozilla Firefox
Reference:
CVE-2014-1557
CVE    1
CVE-2014-1557
CPE    23
cpe:/a:mozilla:firefox_esr:24.5
cpe:/a:mozilla:firefox_esr:24.4
cpe:/a:mozilla:firefox_esr:24.6
cpe:/a:mozilla:firefox_esr
...

© SecPod Technologies