Mozilla Firefox/Thunderbird/SeaMonkey CVE-2014-1481 Security Bypass Vulnerability
BID:65326
Info
Mozilla Firefox/Thunderbird/SeaMonkey CVE-2014-1481 Security Bypass Vulnerability
| Bugtraq ID: | 65326 |
| Class: | Unknown |
| CVE: |
CVE-2014-1481 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2014 12:00AM |
| Updated: | Mar 19 2015 08:27AM |
| Credit: | Boris Zbarsky |
| Vulnerable: |
SuSE openSUSE 11.4 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Mozilla Thunderbird 10.0.1 Mozilla SeaMonkey 2.0.11 Mozilla SeaMonkey 2.0.9 Mozilla SeaMonkey 2.0.8 Mozilla SeaMonkey 2.0.5 Mozilla SeaMonkey 2.0.3 Mozilla SeaMonkey 2.0.2 Mozilla SeaMonkey 2.0.1 Mozilla SeaMonkey 1.1.12 Mozilla SeaMonkey 2.9 Mozilla SeaMonkey 2.8 Mozilla SeaMonkey 2.7.2 Mozilla SeaMonkey 2.7.1 Mozilla SeaMonkey 2.7 Mozilla SeaMonkey 2.6 Mozilla SeaMonkey 2.5 Mozilla SeaMonkey 2.4 Mozilla SeaMonkey 2.3 Mozilla SeaMonkey 2.2 Mozilla SeaMonkey 2.1b2 Mozilla SeaMonkey 2.10 Mozilla SeaMonkey 2.1 Alpha3 Mozilla SeaMonkey 2.1 Alpha2 Mozilla SeaMonkey 2.1 Alpha1 Mozilla SeaMonkey 2.1 Mozilla SeaMonkey 2.0.7 Mozilla SeaMonkey 2.0.6 Mozilla SeaMonkey 2.0.4 Mozilla SeaMonkey 2.0.14 Mozilla SeaMonkey 2.0.13 Mozilla SeaMonkey 2.0.12 Mozilla SeaMonkey 2.0.10 Mozilla SeaMonkey 2.0 Rc2 Mozilla SeaMonkey 2.0 Rc1 Mozilla SeaMonkey 2.0 Beta 2 Mozilla SeaMonkey 2.0 Beta 1 Mozilla SeaMonkey 2.0 Alpha 3 Mozilla SeaMonkey 2.0 Alpha 2 Mozilla SeaMonkey 2.0 Alpha 1 Mozilla SeaMonkey 2.0 Mozilla Firefox ESR 10.0.5 Mozilla Firefox ESR 10.0.4 Mozilla Firefox ESR 10.0.3 Mozilla Firefox ESR 10.0.2 Mozilla Firefox 11.0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 6 |
| Not Vulnerable: | |
Discussion
Mozilla Firefox/Thunderbird/SeaMonkey CVE-2014-1481 Security Bypass Vulnerability
Mozilla Firefox, Thunderbird, and SeaMonkey are prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions; this may aid in launching further attacks.
This issue is fixed in the following versions:
Firefox 27
Firefox ESR 24.3
Thunderbird 24.3
Seamonkey 2.24
Mozilla Firefox, Thunderbird, and SeaMonkey are prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions; this may aid in launching further attacks.
This issue is fixed in the following versions:
Firefox 27
Firefox ESR 24.3
Thunderbird 24.3
Seamonkey 2.24
Exploit / POC
Mozilla Firefox/Thunderbird/SeaMonkey CVE-2014-1481 Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Mozilla Firefox/Thunderbird/SeaMonkey CVE-2014-1481 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Mozilla Firefox/Thunderbird/SeaMonkey CVE-2014-1481 Security Bypass Vulnerability
References:
References:
- Avant Browser 2013 build 115, Released 9.12.2013 (Avant)
- Hooray! Your Cyberfox is up to date. 27.0.0 (8pecxstudios)
- Mozilla Firefox Homepage (Mozilla)
- Mozilla Thunderbird Homepage (Mozilla )
- SeaMonkey Homepage (Mozilla)
- Waterfox 27.0.1 Now Available (Waterfox)
- firefox security update (RHSA-2014-0132) (Avaya)
- Mozilla Foundation Security Advisory 2014-13 (Mozilla)