CVE-2014-1557
published 2014-07-23CVE-2014-1557: The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does not properly…
PriorityP347critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.94%
91.2th percentile
The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does not properly handle the discarding of image data during function execution, which allows remote attackers to execute arbitrary code by triggering prolonged image scaling, as demonstrated by scaling of a high-quality image.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| mozilla | firefox | <= 30.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 31.0+build1-0ubuntu0.14.04.1 | 31.0+build1-0ubuntu0.14.04.1 |
| mozilla | firefox_esr | — | — |
| mozilla | firefox_esr | — | — |
| mozilla | firefox_esr | — | — |
| mozilla | firefox_esr | — | — |
| mozilla | firefox_esr | — | — |
| mozilla | thunderbird | <= 24.6 | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | >= 0 < 1:31.0+build1-0ubuntu0.14.04.1 | 1:31.0+build1-0ubuntu0.14.04.1 |
| oracle | solaris | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7r7x-g5gw-9rgv: The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31
ghsa_unreviewed·2022-05-17
CVE-2014-1557 [HIGH] CWE-94 GHSA-7r7x-g5gw-9rgv: The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31
The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does not properly handle the discarding of image data during function execution, which allows remote attackers to execute arbitrary code by triggering prolonged image scaling, as demonstrated by scaling of a high-quality image.
OSV
firefox vulnerabilities
osv·2014-07-22·CVSS 10.0
[CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Christian Holler, David Keeler, Byron Campen, Gary Kwong, Jesse Ruderman,
Andrew McCreight, Alon Zakai, Bobby Holley, Jonathan Watt, Shu-yu Guo,
Steve Fink, Terrence Cole, Gijs Kruitbosch and Cătălin Badea discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-1547, CVE-2014-1548)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. An attacker could potentially exploit this to cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking Fi
OSV
thunderbird vulnerabilities
osv·2014-07-22·CVSS 10.0
CVE-2014-1547 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Christian Holler, David Keeler and Byron Campen discovered multiple memory
safety issues in Thunderbird. If a user were tricked in to opening a
specially crafted message with scripting enabled, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2014-1547)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. If a user had enabled scripting, an attacker could potentially
exploit this to cause a denial of service via application crash or execute
arbitrary code with the privileges of the user invoking Thunderbird.
(CVE-2014-1549)
Atte Kettunen discovered a use-after-free in WebAudio. If a user had
enabled
OSV
CVE-2014-1557: The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31
osv·2014-07-22·CVSS 9.3
CVE-2014-1557 [CRITICAL] CVE-2014-1557: The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31
The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does not properly handle the discarding of image data during function execution, which allows remote attackers to execute arbitrary code by triggering prolonged image scaling, as demonstrated by scaling of a high-quality image.
Red Hat
Mozilla: Crash in Skia library when scaling high quality images (MFSA 2014-64)
vendor_redhat·2014-07-22·CVSS 9.3
CVE-2014-1557 [CRITICAL] CWE-672 Mozilla: Crash in Skia library when scaling high quality images (MFSA 2014-64)
Mozilla: Crash in Skia library when scaling high quality images (MFSA 2014-64)
The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does not properly handle the discarding of image data during function execution, which allows remote attackers to execute arbitrary code by triggering prolonged image scaling, as demonstrated by scaling of a high-quality image.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2014-07-22·CVSS 10.0
CVE-2014-1547 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Christian Holler, David Keeler and Byron Campen discovered multiple memory
safety issues in Thunderbird. If a user were tricked in to opening a
specially crafted message with scripting enabled, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2014-1547)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. If a user had enabled scripting, an attacker could potentially
exploit this to cause a denial of service via application crash or execute
arbitrary code with the privileges of the user invoking Thunderbird.
(CVE-2014-1549)
Atte Kett
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2014-07-22·CVSS 10.0
CVE-2014-1547 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Christian Holler, David Keeler, Byron Campen, Gary Kwong, Jesse Ruderman,
Andrew McCreight, Alon Zakai, Bobby Holley, Jonathan Watt, Shu-yu Guo,
Steve Fink, Terrence Cole, Gijs Kruitbosch and Cătălin Badea discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-1547, CVE-2014-1548)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. An attacker could potentially exploit this to cause
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-1557 Mozilla: Crash in Skia library when scaling high quality images (MFSA 2014-64)
bugzilla·2014-07-21·CVSS 9.3
CVE-2014-1557 [CRITICAL] CVE-2014-1557 Mozilla: Crash in Skia library when scaling high quality images (MFSA 2014-64)
CVE-2014-1557 Mozilla: Crash in Skia library when scaling high quality images (MFSA 2014-64)
Mozilla community member John reported a crash in the Skia library when scaling high quality images if the scaling operation takes too long. This is caused by the image data being discarded while still in use by the scaling operation. This crash is potentially exploitable on some systems.
In general this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled, but is potentially a risk in browser or browser-like contexts.
External Reference:
http://www.mozilla.org/security/announce/2014/mfsa2014-64.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Mozilla community member John as the
Bugzilla
CVE-2013-1557 OpenJDK: LogStream.setDefaultStream() missing security restrictions (RMI, 8001329)
bugzilla·2013-04-16·CVSS 10.0
CVE-2013-1557 [CRITICAL] CVE-2013-1557 OpenJDK: LogStream.setDefaultStream() missing security restrictions (RMI, 8001329)
CVE-2013-1557 OpenJDK: LogStream.setDefaultStream() missing security restrictions (RMI, 8001329)
It was discovered that LogStream.setDefaultStream() is missing security restrictions. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Discussion:
Public now via Oracle Java SE CPU April 2014:
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html
Fixed in Oracle Java SE 7u21 and 6u45.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0752 https://rhn.redhat.com/errata/RHSA-2013-0752.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0751 https://rhn.redhat.com/errata/RHSA-2013-0751.html
---
OpenJDK7 up
http://linux.oracle.com/errata/ELSA-2014-0918.htmlhttp://secunia.com/advisories/59591http://secunia.com/advisories/59719http://secunia.com/advisories/59760http://secunia.com/advisories/60083http://secunia.com/advisories/60306http://secunia.com/advisories/60486http://secunia.com/advisories/60621http://secunia.com/advisories/60628http://www.debian.org/security/2014/dsa-2986http://www.debian.org/security/2014/dsa-2996http://www.mozilla.org/security/announce/2014/mfsa2014-64.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/68824http://www.securitytracker.com/id/1030619http://www.securitytracker.com/id/1030620https://bugzilla.mozilla.org/show_bug.cgi?id=913805https://security.gentoo.org/glsa/201504-01http://linux.oracle.com/errata/ELSA-2014-0918.htmlhttp://secunia.com/advisories/59591http://secunia.com/advisories/59719http://secunia.com/advisories/59760http://secunia.com/advisories/60083http://secunia.com/advisories/60306http://secunia.com/advisories/60486http://secunia.com/advisories/60621http://secunia.com/advisories/60628http://www.debian.org/security/2014/dsa-2986http://www.debian.org/security/2014/dsa-2996http://www.mozilla.org/security/announce/2014/mfsa2014-64.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/68824http://www.securitytracker.com/id/1030619http://www.securitytracker.com/id/1030620https://bugzilla.mozilla.org/show_bug.cgi?id=913805https://security.gentoo.org/glsa/201504-01
2014-07-23
Published