Your submission was sent successfully! Close

CVE-2014-1580

Published: 14 October 2014

Mozilla Firefox before 33.0 does not properly initialize memory for GIF images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers a sequence of rendering operations for truncated GIF data within a CANVAS element.

Priority

Medium

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
lucid Ignored
(reached end of life)
precise
Released (33.0+build2-0ubuntu0.12.04.1)
trusty Does not exist
(trusty was released [33.0+build2-0ubuntu0.14.04.1])
upstream
Released (33.0)