CVE-2014-1577
published 2014-10-15CVE-2014-1577: The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and…
PriorityP424medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
2.84%
85.3th percentile
The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read, memory corruption, and application crash) via an invalid custom waveform that triggers a calculation of a negative frequency value.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 32.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 33.0+build2-0ubuntu0.14.04.1 | 33.0+build2-0ubuntu0.14.04.1 |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | >= 0 < 1:31.2.0+build2-0ubuntu0.14.04.1 | 1:31.2.0+build2-0ubuntu0.14.04.1 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jasper: double free issue in jas_iccattrval_destroy()
vendor_redhat·2016-03-03·CVSS 6.8
CVE-2016-1577 [MEDIUM] CWE-416 jasper: double free issue in jas_iccattrval_destroy()
jasper: double free issue in jas_iccattrval_destroy()
Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file, a different vulnerability than CVE-2014-8137.
Package: netpbm (Red Hat Enterprise Linux 5) - Not affected
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Will not fix
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2014-10-15·CVSS 7.5
CVE-2014-1574 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Bobby Holley, Christian Holler, David Bolter, Byron Campen and Jon
Coppeard discovered multiple memory safety issues in Thunderbird. If a
user were tricked in to opening a specially crafted message with scripting
enabled, an attacker could potentially exploit these to cause a denial of
service via application crash, or execute arbitrary code with the
privileges of the user invoking Thunderbird. (CVE-2014-1574)
Atte Kettunen discovered a buffer overflow during CSS manipulation. If a
user were tricked in to opening a specially crafted message, an attacker
could potentially exploit this to cause a denial of service via
application crash or execute arbitrary code with the privileges of the
user in
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2014-10-14·CVSS 7.5
CVE-2014-1574 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Bobby Holley, Christian Holler, David Bolter, Byron Campen, Jon Coppeard,
Carsten Book, Martijn Wargers, Shih-Chiang Chien, Terrence Cole and
Jeff Walden discovered multiple memory safety issues in Firefox. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2014-1574, CVE-2014-1575)
Atte Kettunen discovered a buffer overflow during CSS manipulation. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause
Red Hat
Mozilla: Web Audio memory corruption issues with custom waveforms (MFSA 2014-76)
vendor_redhat·2014-10-14·CVSS 6.4
CVE-2014-1577 [MEDIUM] Mozilla: Web Audio memory corruption issues with custom waveforms (MFSA 2014-76)
Mozilla: Web Audio memory corruption issues with custom waveforms (MFSA 2014-76)
The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read, memory corruption, and application crash) via an invalid custom waveform that triggers a calculation of a negative frequency value.
GHSA
GHSA-82w9-49hw-6739: The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 33
ghsa_unreviewed·2022-05-17
CVE-2014-1577 [MEDIUM] GHSA-82w9-49hw-6739: The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 33
The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read, memory corruption, and application crash) via an invalid custom waveform that triggers a calculation of a negative frequency value.
OSV
thunderbird vulnerabilities
osv·2014-10-15·CVSS 7.5
CVE-2014-1574 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Bobby Holley, Christian Holler, David Bolter, Byron Campen and Jon
Coppeard discovered multiple memory safety issues in Thunderbird. If a
user were tricked in to opening a specially crafted message with scripting
enabled, an attacker could potentially exploit these to cause a denial of
service via application crash, or execute arbitrary code with the
privileges of the user invoking Thunderbird. (CVE-2014-1574)
Atte Kettunen discovered a buffer overflow during CSS manipulation. If a
user were tricked in to opening a specially crafted message, an attacker
could potentially exploit this to cause a denial of service via
application crash or execute arbitrary code with the privileges of the
user invoking Thunderbird. (CVE-2014-1576)
Holger Fuhrmannek discovered an
OSV
firefox vulnerabilities
osv·2014-10-14·CVSS 7.5
CVE-2014-1574 [HIGH] firefox vulnerabilities
firefox vulnerabilities
Bobby Holley, Christian Holler, David Bolter, Byron Campen, Jon Coppeard,
Carsten Book, Martijn Wargers, Shih-Chiang Chien, Terrence Cole and
Jeff Walden discovered multiple memory safety issues in Firefox. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2014-1574, CVE-2014-1575)
Atte Kettunen discovered a buffer overflow during CSS manipulation. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via
application crash or execute arbitrary code with the privileges of the
user invoking Fir
OSV
CVE-2014-1577: The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 33
osv·2014-10-14·CVSS 6.4
CVE-2014-1577 [MEDIUM] CVE-2014-1577: The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 33
The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read, memory corruption, and application crash) via an invalid custom waveform that triggers a calculation of a negative frequency value.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-1577 Mozilla: Web Audio memory corruption issues with custom waveforms (MFSA 2014-76)
bugzilla·2014-10-14·CVSS 6.4
CVE-2014-1577 [MEDIUM] CVE-2014-1577 Mozilla: Web Audio memory corruption issues with custom waveforms (MFSA 2014-76)
CVE-2014-1577 Mozilla: Web Audio memory corruption issues with custom waveforms (MFSA 2014-76)
Security researcher Holger Fuhrmannek used the used the Address Sanitizer tool to discover an out-of-bounds read issue with Web Audio when interacting with custom waveforms with invalid values. This results in a crash and could allow for the reading of random memory which may contain sensitive data, or of memory addresses that could be used in combination with another bug.
In general this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled, but is potentially a risk in browser or browser-like contexts.
External Reference:
http://www.mozilla.org/security/announce/2014/mfsa2014-76.html
Acknowledgements:
Red Hat would like to thank the Mozilla proj
arXiv
Browser Feature Usage on the Modern Web
arxiv_fulltext·2016-05-20
Browser Feature Usage on the Modern Web
Browser Feature Usage on the Modern Web
4
Peter Snyder
[email protected]
Lara Ansari
[email protected]
Cynthia Taylor
[email protected]
Chris Kanich
[email protected]
Department of Computer Science
University of Illinois at Chicago
Chicago, IL 60607
Draft:
CDF
HTML and JavaScript
HTML
commodity web browsers
JavaScript
cross-site scripting
[1]
#1.
1,392
74
186
470
111
Firefox
46.0.1
[1]red#1
## Abstract
Modern web browsers are incredibly complex, with millions of lines of code and
over one thousand functions and properties available to website authors.
This work investigates how these browser features are used on the modern, open
web. We find that features differ wildly in popularity, with over 50% of
provided features never used in the Alexa 10k.
We also look at how popular ad an
http://lists.fedoraproject.org/pipermail/package-announce/2014-November/141796.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/141085.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-01/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1635.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1647.htmlhttp://secunia.com/advisories/61387http://secunia.com/advisories/61854http://secunia.com/advisories/62021http://secunia.com/advisories/62022http://secunia.com/advisories/62023http://www.debian.org/security/2014/dsa-3050http://www.debian.org/security/2014/dsa-3061http://www.mozilla.org/security/announce/2014/mfsa2014-76.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/70440http://www.securitytracker.com/id/1031028http://www.securitytracker.com/id/1031030http://www.ubuntu.com/usn/USN-2372-1http://www.ubuntu.com/usn/USN-2373-1https://advisories.mageia.org/MGASA-2014-0421.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1012609https://security.gentoo.org/glsa/201504-01http://lists.fedoraproject.org/pipermail/package-announce/2014-November/141796.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/141085.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-01/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1635.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1647.htmlhttp://secunia.com/advisories/61387http://secunia.com/advisories/61854http://secunia.com/advisories/62021http://secunia.com/advisories/62022http://secunia.com/advisories/62023http://www.debian.org/security/2014/dsa-3050http://www.debian.org/security/2014/dsa-3061http://www.mozilla.org/security/announce/2014/mfsa2014-76.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/70440http://www.securitytracker.com/id/1031028http://www.securitytracker.com/id/1031030http://www.ubuntu.com/usn/USN-2372-1http://www.ubuntu.com/usn/USN-2373-1https://advisories.mageia.org/MGASA-2014-0421.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1012609https://security.gentoo.org/glsa/201504-01
2014-10-15
Published