Mozilla Firefox ESR < 24.6 Multiple Vulnerabilities

medium Nessus Network Monitor Plugin ID 701245

Synopsis

The remote host has a web browser installed that is vulnerable to multiple attack vectors.

Description

Versions of Mozilla Firefox ESR prior to 24.6 are unpatched against the following vulnerabilities :

- Buffer overflows due to insufficient input validation in Gamepad API and Web Audio Speex resampler, which can be leveraged to execute arbitrary code or cause denial of service conditions (CVE-2014-1543, CVE-2014-1542)
- Use-after-free errors in SMIL Animation Controller, Event Listener Manager, and various other locations, which may be triggered via web content to cause a potentially exploitable crash (CVE-2014-1540, CVE-2014-1539, CVE-2014-1536, CVE-2014-1537)
- Clickjacking through cursor invisibility when the cursor leaves the embedded flash object (OS X platform only) (CVE-2014-1539)
- Miscellaneous memory safety hazards (CVE-2014-1533, CVE-2014-1534)

Solution

Upgrade to Firefox ESR versions 24.6, or later.

See Also

http://www.mozilla.org/security/announce/2014/mfsa2014-48.html

http://www.mozilla.org/security/announce/2014/mfsa2014-49.html

http://www.mozilla.org/security/announce/2014/mfsa2014-50.html

http://www.mozilla.org/security/announce/2014/mfsa2014-51.html

http://www.mozilla.org/security/announce/2014/mfsa2014-52.html

http://www.mozilla.org/security/announce/2014/mfsa2014-53.html

http://www.mozilla.org/security/announce/2014/mfsa2014-54.html

http://www.mozilla.org/security/announce/2014/mfsa2014-55.html

Plugin Details

Severity: Medium

ID: 701245

Family: Web Clients

Published: 11/6/2019

Updated: 11/6/2019

Nessus ID: 74440

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: Medium

Base Score: 5.6

Temporal Score: 5.4

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:X/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:mozilla:firefox_esr

Patch Publication Date: 6/10/2014

Vulnerability Publication Date: 6/10/2014

Reference Information

CVE: CVE-2014-1533, CVE-2014-1534, CVE-2014-1536, CVE-2014-1537, CVE-2014-1538, CVE-2014-1539, CVE-2014-1540, CVE-2014-1541, CVE-2014-1542, CVE-2014-1543, CVE-2014-1545

BID: 67964, 67965, 67966, 67967, 67968, 67969, 67971, 67975, 67976, 67978, 67979