Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-1557
HistoryJul 22, 2014 - 12:00 a.m.

CVE-2014-1557

2014-07-2200:00:00
ubuntu.com
ubuntu.com
17

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.017

Percentile

88.0%

The ConvolveHorizontally function in Skia, as used in Mozilla Firefox
before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7,
does not properly handle the discarding of image data during function
execution, which allows remote attackers to execute arbitrary code by
triggering prolonged image scaling, as demonstrated by scaling of a
high-quality image.

OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchfirefox< 31.0+build1-0ubuntu0.12.04.1UNKNOWN
ubuntu14.04noarchfirefox< 31.0+build1-0ubuntu0.14.04.1UNKNOWN
ubuntu12.04noarchthunderbird< 1:31.0+build1-0ubuntu0.12.04.1UNKNOWN
ubuntu14.04noarchthunderbird< 1:31.0+build1-0ubuntu0.14.04.1UNKNOWN

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.017

Percentile

88.0%