Lucene search

K
mozillaMozilla FoundationMFSA2014-64
HistoryJul 22, 2014 - 12:00 a.m.

Crash in Skia library when scaling high quality images — Mozilla

2014-07-2200:00:00
Mozilla Foundation
www.mozilla.org
29

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.017

Percentile

88.0%

Mozilla community member John reported a crash in the Skia library when scaling high quality images if the scaling operation takes too long. This is caused by the image data being discarded while still in use by the scaling operation. This crash is potentially exploitable on some systems.

Affected configurations

Vulners
Node
mozillafirefoxRange<31
OR
mozillafirefox_esrRange<24.7
OR
mozillathunderbirdRange<24.7
OR
mozillathunderbirdRange<31

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.017

Percentile

88.0%