1
PublicDateAtUSN: 2014-03-18
2
Candidate: CVE-2014-1497
5
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1497
6
http://www.mozilla.org/security/announce/2014/mfsa2014-17.html
7
https://usn.ubuntu.com/usn/usn-2150-1
8
https://usn.ubuntu.com/usn/usn-2151-1
10
The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before
11
28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey
12
before 2.25 allows remote attackers to obtain sensitive information from
13
process heap memory, cause a denial of service (out-of-bounds read and
14
application crash), or possibly have unspecified other impact via a crafted
21
Assigned-to: chrisccoulson
24
upstream_firefox: released (28.0)
25
lucid_firefox: ignored (reached end-of-life)
26
precise_firefox: released (28.0+build2-0ubuntu0.12.04.1)
27
quantal_firefox: released (28.0+build2-0ubuntu0.12.10.1)
28
saucy_firefox: released (28.0+build2-0ubuntu0.13.10.1)
29
devel_firefox: released (28.0+build2-0ubuntu1)
32
Priority_thunderbird: low
33
upstream_thunderbird: released (24.4.0)
34
lucid_thunderbird: ignored (reached end-of-life)
35
precise_thunderbird: released (1:24.4.0+build1-0ubuntu0.12.04.1)
36
quantal_thunderbird: released (1:24.4.0+build1-0ubuntu0.12.10.1)
37
saucy_thunderbird: released (1:24.4.0+build1-0ubuntu0.13.10.2)
38
devel_thunderbird: released (1:24.4.0+build1-0ubuntu1)