{"id":"MGASA-2014-0419","summary":"Updated iceape package fixes security vulnerabilities","details":"Multiple unspecified vulnerabilities in the browser engine in Mozilla \nFirefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird \nbefore 24.6 allow remote attackers to cause a denial of service \n(memory corruption and application crash) or possibly execute \narbitrary code via unknown vectors. (CVE-2014-1533)\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla \nFirefox before 30.0 allow remote attackers to cause a denial of \nservice (memory corruption and application crash) or possibly execute \narbitrary code via unknown vectors. (CVE-2014-1534)\n\nThe PropertyProvider::FindJustificationRange function in Mozilla \nFirefox before 30.0 allows remote attackers to execute arbitrary code \nor cause a denial of service (out-of-bounds read) via unspecified \nvectors. (CVE-2014-1536)\n\nUse-after-free vulnerability in the \nmozilla::dom::workers::WorkerPrivateParent function in Mozilla Firefox \nbefore 30.0 allows remote attackers to execute arbitrary code or cause \na denial of service (heap memory corruption) via unspecified vectors. \n(CVE-2014-1537)\n\nUse-after-free vulnerability in the nsTextEditRules::CreateMozBR \nfunction in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, \nand Thunderbird before 24.6 allows remote attackers to execute \narbitrary code or cause a denial of service (heap memory corruption) \nvia unspecified vectors. (CVE-2014-1538)\n\nUse-after-free vulnerability in the \nnsEventListenerManager::CompileEventHandlerInternal function in the \nEvent Listener Manager in Mozilla Firefox before 30.0 allows remote \nattackers to execute arbitrary code or cause a denial of service (heap \nmemory corruption) via crafted web content. (CVE-2014-1540)\n\nUse-after-free vulnerability in the RefreshDriverTimer::Tick*Driver \nfunction in the SMIL Animation Controller in Mozilla Firefox before \n30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allows \nremote attackers to execute arbitrary code or cause a denial of \nservice (heap memory corruption) via crafted web content. \n(CVE-2014-1541)\n\nBuffer overflow in the Speex resampler in the Web Audio subsystem in \nMozilla Firefox before 30.0 allows remote attackers to execute \narbitrary code via vectors related to a crafted AudioBuffer channel \ncount and sample rate. (CVE-2014-1542)\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla \nFirefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird \nbefore 24.7 allow remote attackers to cause a denial of service \n(memory corruption and application crash) or possibly execute \narbitrary code via unknown vectors. (CVE-2014-1547)\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla \nFirefox before 31.0 and Thunderbird before 31.0 allow remote attackers \nto cause a denial of service (memory corruption and application crash) \nor possibly execute arbitrary code via unknown vectors. \n(CVE-2014-1548)\n\nThe mozilla::dom::AudioBufferSourceNodeEngine::CopyFromInputBuffer \nfunction in Mozilla Firefox before 31.0 and Thunderbird before 31.0 \ndoes not properly allocate Web Audio buffer memory, which allows \nremote attackers to execute arbitrary code or cause a denial of \nservice (buffer overflow and application crash) via crafted audio \ncontent that is improperly handled during playback buffering. \n(CVE-2014-1549)\n\nUse-after-free vulnerability in the MediaInputPort class in Mozilla \nFirefox before 31.0 and Thunderbird before 31.0 allows remote \nattackers to execute arbitrary code or cause a denial of service (heap \nmemory corruption) by leveraging incorrect Web Audio control-message \nordering. (CVE-2014-1550)\n\nMozilla Firefox before 31.0 does not properly restrict use of \ndrag-and-drop events to spoof customization events, which allows \nremote attackers to alter the placement of UI icons via crafted \nJavaScript code that is encountered during (1) page, (2) panel, or (3) \ntoolbar customization. (CVE-2014-1561)\n\nUse-after-free vulnerability in the nsDocLoader::OnProgress function \nin Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and \nThunderbird before 24.7 allows remote attackers to execute arbitrary \ncode via vectors that trigger a FireOnStateChange event. \n(CVE-2014-1555)\n\nMozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and \nThunderbird before 24.7 allow remote attackers to execute arbitrary \ncode via crafted WebGL content constructed with the Cesium JavaScript \nlibrary. (CVE-2014-1556)\n\nThe ConvolveHorizontally function in Skia, as used in Mozilla Firefox \nbefore 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before \n24.7, does not properly handle the discarding of image data during \nfunction execution, which allows remote attackers to execute arbitrary \ncode by triggering prolonged image scaling, as demonstrated by scaling \nof a high-quality image. (CVE-2014-1557)\n\nMozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote \nattackers to cause a denial of service (X.509 certificate parsing \noutage) via a crafted certificate that does not use UTF-8 character \nencoding in a required context, a different vulnerability than \nCVE-2014-1559. (CVE-2014-1558)\n\nMozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote \nattackers to cause a denial of service (X.509 certificate parsing \noutage) via a crafted certificate that does not use UTF-8 character \nencoding in a required context, a different vulnerability than \nCVE-2014-1558. (CVE-2014-1559)\n\nMozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote \nattackers to cause a denial of service (X.509 certificate parsing \noutage) via a crafted certificate that does not use ASCII character \nencoding in a required context. (CVE-2014-1560)\n\nMozilla Firefox before 31.0 and Thunderbird before 31.0 do not \nproperly implement the sandbox attribute of the IFRAME element, which \nallows remote attackers to bypass intended restrictions on same-origin \ncontent via a crafted web site in conjunction with a redirect. \n(CVE-2014-1552)\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla \nFirefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird \n31.x before 31.1 allow remote attackers to cause a denial of service \n(memory corruption and application crash) or possibly execute \narbitrary code via unknown vectors. (CVE-2014-1553)\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla \nFirefox before 32.0 allow remote attackers to cause a denial of \nservice (memory corruption and application crash) or possibly execute \narbitrary code via unknown vectors. (CVE-2014-1554)\n\nUnspecified vulnerability in the browser engine in Mozilla Firefox \nbefore 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and \nThunderbird 24.x before 24.8 and 31.x before 31.1 allows remote \nattackers to cause a denial of service (memory corruption and \napplication crash) or possibly execute arbitrary code via unknown \nvectors. (CVE-2014-1562)\n\nUse-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff \nfunction in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, \nand Thunderbird 31.x before 31.1 allows remote attackers to execute \narbitrary code or cause a denial of service (heap memory corruption) \nvia an SVG animation with DOM interaction that triggers incorrect \ncycle collection. (CVE-2014-1563)\n\nMozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and \nThunderbird 31.x before 31.1 do not properly initialize memory for GIF \nrendering, which allows remote attackers to obtain sensitive \ninformation from process memory via crafted web script that interacts \nwith a CANVAS element associated with a malformed GIF image. \n(CVE-2014-1564)\n\nUse-after-free vulnerability in DirectionalityUtils.cpp in Mozilla \nFirefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before \n31.1, and Thunderbird 24.x before 24.8 and 31.x before 31.1 allows \nremote attackers to execute arbitrary code via text that is improperly \nhandled during the interaction between directionality resolution and \nlayout. (CVE-2014-1567)\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla \nFirefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird \n31.x before 31.2 allow remote attackers to cause a denial of service \n(memory corruption and application crash) or possibly execute \narbitrary code via unknown vectors. (CVE-2014-1574)\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla \nFirefox before 33.0 allow remote attackers to cause a denial of \nservice (memory corruption and application crash) or possibly execute \narbitrary code via vectors related to improper interaction between \nthreading and garbage collection in the GCRuntime::triggerGC function \nin js/src/jsgc.cpp, and unknown other vectors. ()\n\nHeap-based buffer overflow in the nsTransformedTextRun function in \nMozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and \nThunderbird 31.x before 31.2 allows remote attackers to execute \narbitrary code via Cascading Style Sheets (CSS) token sequences that \ntrigger changes to capitalization style. (CVE-2014-1576)\n\nThe mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the \nWeb Audio subsystem in Mozilla Firefox before 33.0, Firefox ESR 31.x \nbefore 31.2, and Thunderbird 31.x before 31.2 allows remote attackers \nto obtain sensitive information from process memory or cause a denial \nof service (out-of-bounds read, memory corruption, and application \ncrash) via an invalid custom waveform that triggers a calculation of a \nnegative frequency value. (CVE-2014-1577)\n\nThe get_tile function in Mozilla Firefox before 33.0, Firefox ESR 31.x \nbefore 31.2, and Thunderbird 31.x before 31.2 allows remote attackers \nto cause a denial of service (out-of-bounds write and application \ncrash) or possibly execute arbitrary code via WebM frames with invalid \ntile sizes that are improperly handled in buffering operations during \nvideo playback. (CVE-2014-1578)\n\nMozilla Firefox before 33.0 does not properly initialize memory for \nGIF images, which allows remote attackers to obtain sensitive \ninformation from process memory via a crafted web page that triggers a \nsequence of rendering operations for truncated GIF data within a \nCANVAS element. (CVE-2014-1580)\n\nUse-after-free vulnerability in DirectionalityUtils.cpp in Mozilla \nFirefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird \n31.x before 31.2 allows remote attackers to execute arbitrary code via \ntext that is improperly handled during the interaction between \ndirectionality resolution and layout. (CVE-2014-1581)\n\nThe Public Key Pinning (PKP) implementation in Mozilla Firefox before \n33.0 does not properly consider the connection-coalescing behavior of \nSPDY and HTTP/2 in the case of a shared IP address, which allows \nman-in-the-middle attackers to bypass an intended pinning \nconfiguration and spoof a web site by providing a valid certificate \nfrom an arbitrary recognized Certification Authority. (CVE-2014-1582)\n\nThe Public Key Pinning (PKP) implementation in Mozilla Firefox before \n33.0 skips pinning checks upon an unspecified issuer-verification \nerror, which makes it easier for remote attackers to bypass an \nintended pinning configuration and spoof a web site via a crafted \ncertificate that leads to presentation of the Untrusted Connection \ndialog to the user. (CVE-2014-1584)\n\nThe WebRTC video-sharing feature in dom/media/MediaManager.cpp in \nMozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and \nThunderbird 31.x before 31.2 does not properly recognize Stop Sharing \nactions for videos in IFRAME elements, which allows remote attackers \nto obtain sensitive information from the local camera by maintaining a \nsession after the user tries to discontinue streaming. (CVE-2014-1585)\n\ncontent/base/src/nsDocument.cpp in Mozilla Firefox before 33.0, \nFirefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 does \nnot consider whether WebRTC video sharing is occurring, which allows \nremote attackers to obtain sensitive information from the local camera \nin certain IFRAME situations by maintaining a session after the user \ntemporarily navigates away. (CVE-2014-1586)\n\nThe Alarm API in Mozilla Firefox before 33.0 and Firefox ESR 31.x \nbefore 31.2 does not properly restrict toJSON calls, which allows \nremote attackers to bypass the Same Origin Policy via crafted API \ncalls that access sensitive information within the JSON data of an \nalarm. (CVE-2014-1583)\n","modified":"2026-04-16T06:23:17.281948362Z","published":"2014-10-23T13:27:57Z","upstream":["CVE-2014-1533","CVE-2014-1534","CVE-2014-1536","CVE-2014-1537","CVE-2014-1538","CVE-2014-1540","CVE-2014-1541","CVE-2014-1542","CVE-2014-1547","CVE-2014-1548","CVE-2014-1549","CVE-2014-1550","CVE-2014-1552","CVE-2014-1553","CVE-2014-1554","CVE-2014-1555","CVE-2014-1556","CVE-2014-1557","CVE-2014-1558","CVE-2014-1559","CVE-2014-1560","CVE-2014-1561","CVE-2014-1562","CVE-2014-1563","CVE-2014-1564","CVE-2014-1565","CVE-2014-1567","CVE-2014-1574","CVE-2014-1575","CVE-2014-1576","CVE-2014-1577","CVE-2014-1578","CVE-2014-1580","CVE-2014-1581","CVE-2014-1582","CVE-2014-1583","CVE-2014-1584","CVE-2014-1585","CVE-2014-1586"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0419.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=14318"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-48.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-49.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-51.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-52.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-53.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-56.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-57.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-58.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-60.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-61.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-62.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-64.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-65.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-66.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-67.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-68.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-69.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-70.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-72.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-74.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-75.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-76.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-77.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-78.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-79.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-80.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-81.html"},{"type":"WEB","url":"https://www.mozilla.org/security/announce/2014/mfsa2014-82.html"}],"affected":[{"package":{"name":"iceape","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/iceape?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.30-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0419.json"}},{"package":{"name":"iceape","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/iceape?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.30-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0419.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}