Name | CVE-2014-1578 |
Description | The get_tile function in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly execute arbitrary code via WebM frames with invalid tile sizes that are improperly handled in buffering operations during video playback. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more) |
References | DSA-3050-1, DSA-3061-1 |
Debian Bugs | 765435 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
icedove (PTS) | jessie | 1:52.3.0-4~deb8u2 | fixed |
libvpx (PTS) | jessie, jessie (lts) | 1.3.0-3+deb8u3 | fixed |
stretch (security), stretch (lts), stretch | 1.6.1-3+deb9u3 | fixed | |
buster, buster (security) | 1.7.0-3+deb10u1 | fixed | |
bullseye | 1.9.0-1 | fixed | |
sid, bookworm | 1.12.0-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
icedove | source | squeeze | (unfixed) | end-of-life | ||
icedove | source | wheezy | 31.2.0-1~deb7u1 | DSA-3061-1 | ||
icedove | source | (unstable) | 31.2.0-1 | |||
iceweasel | source | squeeze | (unfixed) | end-of-life | ||
iceweasel | source | wheezy | 31.2.0esr-2~deb7u1 | DSA-3050-1 | ||
iceweasel | source | (unstable) | 31.2.0esr-1 | |||
libvpx | source | squeeze | (not affected) | |||
libvpx | source | wheezy | (not affected) | |||
libvpx | source | (unstable) | 1.3.0-3 | 765435 |
[wheezy] - libvpx <not-affected> (vp9 codec not yet present)
[squeeze] - libvpx <not-affected> (vp9 codec not yet present)
https://www.mozilla.org/security/announce/2014/mfsa2014-77.html
https://hg.mozilla.org/releases/mozilla-esr31/rev/6023f0b4f8ba