Summary
This host is installed with Mozilla Firefox
and is prone to multiple vulnerabilities.
Impact
Successful exploitation will allow attackers
disclose potentially sensitive information, bypass certain security restrictions, conduct denial-of-service attack and compromise a user's system.
Impact Level: System/Application
Solution
Upgrade to Mozilla Firefox version 33.0
or later, For updates refer to http://www.mozilla.com/en-US/firefox/all.html
Insight
Multiple flaws exist due to,
- An error in Alarm API which does not properly restrict toJSON calls.
- An error when handling video sharing within a WebRTC session running within an iframe.
- Multiple errors in the Public Key Pinning (PKP) implementation.
- An use-after-free error when handling text layout related to DirectionalityUtils.
- An error when repeatedly rendering a GIF image within a canvas element.
- An out-of-bounds error within the 'get_tile' function when buffering WebM format video containing frames.
- An out-of-bounds error within 'mozilla::dom::OscillatorNodeEngine::ComputeCustom' method when interacting with custom waveforms.
- An error within the 'nsTransformedTextRun' class when handling capitalization style changes during CSS parsing.
- An error when handling camera recording within an iframe related to site navigation.
- Other unspecified errors.
Affected
Mozilla Firefox before version 33.0 on
Mac OS X
Detection
Get the installed version with the help of
detect NVT and check the version is vulnerable or not.
References
- http://msisac.cisecurity.org/advisories/2014/2014-088.cfm
- http://osvdb.com/113159
- http://osvdb.com/113161
- http://secunia.com/advisories/59643/
- https://www.mozilla.org/security/announce/2014/mfsa2014-76.html
- https://www.mozilla.org/security/announce/2014/mfsa2014-81.html
- https://www.mozilla.org/security/announce/2014/mfsa2014-82.html
Updated on 2017-03-28
Severity
Classification
-
CVE CVE-2014-1574, CVE-2014-1575, CVE-2014-1576, CVE-2014-1577, CVE-2014-1578, CVE-2014-1580, CVE-2014-1581, CVE-2014-1582, CVE-2014-1583, CVE-2014-1584, CVE-2014-1585, CVE-2014-1586 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities