{"id":"MGASA-2014-0201","summary":"Updated firefox & thunderbird packages fix multiple vulnerabilities","details":"Updated firefox and thunderbird packages fix security vulnerabilities:\n\nSeveral flaws were found in the processing of malformed web content. A web\npage containing malicious content could cause Firefox or Thunderbird to\ncrash or, potentially, execute arbitrary code with the privileges of the\nuser running it (CVE-2014-1518, CVE-2014-1524, CVE-2014-1529,\nCVE-2014-1531).\n\nA use-after-free flaw was found in the way Firefox and Thunderbird resolved\nhosts in certain circumstances. An attacker could use this flaw to crash\nFirefox or Thunderbird or, potentially, execute arbitrary code with the\nprivileges of the user running it (CVE-2014-1532).\n\nAn out-of-bounds read flaw was found in the way Firefox and Thunderbird\ndecoded JPEG images. Loading a web page containing a specially crafted JPEG\nimage could cause Firefox or Thunderbird to crash (CVE-2014-1523).\n\nA flaw was found in the way Firefox and Thunderbird handled browser\nnavigations through history. An attacker could possibly use this flaw to\ncause the address bar of the browser to display a web page name while\nloading content from an entirely different web page, which could allow for\ncross-site scripting (XSS) attacks (CVE-2014-1530).\n","modified":"2026-04-16T06:22:53.192201834Z","published":"2014-05-02T18:03:24Z","upstream":["CVE-2014-1518","CVE-2014-1523","CVE-2014-1524","CVE-2014-1529","CVE-2014-1530","CVE-2014-1531","CVE-2014-1532"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0201.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2014/mfsa2014-34.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2014/mfsa2014-37.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2014/mfsa2014-38.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2014/mfsa2014-42.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2014/mfsa2014-43.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2014/mfsa2014-44.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2014/mfsa2014-46.html"},{"type":"WEB","url":"http://www.mozilla.org/security/known-vulnerabilities/firefoxESR.html"},{"type":"WEB","url":"http://www.mozilla.org/security/known-vulnerabilities/thunderbird.html"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2014-0448.html"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2014-0449.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=13293"}],"affected":[{"package":{"name":"firefox","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/firefox?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.5.0-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0201.json"}},{"package":{"name":"firefox-l10n","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.5.0-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0201.json"}},{"package":{"name":"thunderbird","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.5.0-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0201.json"}},{"package":{"name":"thunderbird-l10n","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.5.0-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0201.json"}},{"package":{"name":"firefox","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/firefox?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.5.0-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0201.json"}},{"package":{"name":"firefox-l10n","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.5.0-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0201.json"}},{"package":{"name":"thunderbird","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.5.0-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0201.json"}},{"package":{"name":"thunderbird-l10n","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.5.0-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0201.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}