{"id":"MGASA-2015-0028","summary":"Updated iceape package fixes security vulnerabilities","details":"Updated iceape packages fix security issues:\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla Firefox \nbefore 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and \nSeaMonkey before 2.32 allow remote attackers to cause a denial of service \n(memory corruption and application crash) or possibly execute arbitrary code via \nunknown vectors. (CVE-2014-8634)\n\nMultiple unspecified vulnerabilities in the browser engine in Mozilla Firefox \nbefore 35.0 and SeaMonkey before 2.32 allow remote attackers to cause a denial \nof service (memory corruption and application crash) or possibly execute \narbitrary code via unknown vectors. (CVE-2014-8635)\n\nMozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize \nmemory for BMP images, which allows remote attackers to obtain sensitive \ninformation from process memory via a crafted web page that triggers the \nrendering of malformed BMP data within a CANVAS element. (CVE-2014-8637)\n\nThe navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox \nESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits \nthe CORS Origin header, which allows remote attackers to bypass intended CORS \naccess-control checks and conduct cross-site request forgery (CSRF) attacks via \na crafted web site. (CVE-2014-8638)\n\nMozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before \n31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers \nwithin responses that have a 407 (aka Proxy Authentication Required) status \ncode, which allows remote HTTP proxy servers to conduct session fixation attacks \nby providing a cookie name that corresponds to the session cookie of the origin \nserver.(CVE-2014-8639)\n\nThe mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the Web \nAudio API implementation in Mozilla Firefox before 35.0 and SeaMonkey before \n2.32 does not properly restrict timeline operations, which allows remote \nattackers to cause a denial of service (uninitialized-memory read and \napplication crash) via crafted API calls. (CVE-2014-8640)\n\nUse-after-free vulnerability in the WebRTC implementation in Mozilla Firefox \nbefore 35.0, Firefox ESR 31.x before 31.4, and SeaMonkey before 2.32 allows \nremote attackers to execute arbitrary code via crafted track data. \n(CVE-2014-8641)\n\nMozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the \nid-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, \nwhich makes it easier for remote attackers to obtain sensitive information by \nsniffing the network during a session in which there was an incorrect decision \nto accept a compromised and revoked certificate. (CVE-2014-8642)\n\nThe XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey \nbefore 2.32 does not properly interact with a DOM object that has a named \ngetter, which might allow remote attackers to execute arbitrary JavaScript code \nwith chrome privileges via unspecified vectors. (CVE-2014-8636)\n","modified":"2026-04-16T06:25:04.880674922Z","published":"2015-01-19T16:47:36Z","upstream":["CVE-2014-8634","CVE-2014-8635","CVE-2014-8636","CVE-2014-8637","CVE-2014-8638","CVE-2014-8639","CVE-2014-8640","CVE-2014-8641","CVE-2014-8642"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0028.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=15044"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2015-01/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2015-02/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2015-03/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2015-04/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2015-05/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2015-06/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2015-08/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2015-09/"}],"affected":[{"package":{"name":"iceape","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/iceape?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.32-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0028.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}