~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2014-1565

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2014-09-02
2
 
Candidate: CVE-2014-1565
3
 
PublicDate: 2014-09-03
4
 
References: 
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1565
6
 
 https://www.mozilla.org/security/announce/2014/mfsa2014-70.html
7
 
 https://usn.ubuntu.com/usn/usn-2329-1
8
 
 https://usn.ubuntu.com/usn/usn-2330-1
9
 
Description:
10
 
 The mozilla::dom::AudioEventTimeline function in the Web Audio API
11
 
 implementation in Mozilla Firefox before 32.0, Firefox ESR 31.x before
12
 
 31.1, and Thunderbird 31.x before 31.1 does not properly create audio
13
 
 timelines, which allows remote attackers to obtain sensitive information
14
 
 from process memory or cause a denial of service (out-of-bounds read) via
15
 
 crafted API calls.
16
 
Ubuntu-Description: 
17
 
Notes: 
18
 
Bugs: 
19
 
Priority: medium
20
 
Discovered-by:
21
 
Assigned-to: chrisccoulson
22
 
 
23
 
Patches_firefox:
24
 
upstream_firefox: released (32.0)
25
 
lucid_firefox: ignored (reached end-of-life)
26
 
precise_firefox: released (32.0+build1-0ubuntu0.12.04.1)
27
 
trusty_firefox: released (32.0+build1-0ubuntu0.14.04.1)
28
 
devel_firefox: released (32.0+build1-0ubuntu1)
29
 
 
30
 
Patches_thunderbird:
31
 
Priority_thunderbird: low
32
 
upstream_thunderbird: released (31.1.0)
33
 
lucid_thunderbird: ignored (reached end-of-life)
34
 
precise_thunderbird: released (1:31.1.0+build2-0ubuntu0.12.04.1)
35
 
trusty_thunderbird: released (1:31.1.0+build2-0ubuntu0.14.04.1)
36
 
devel_thunderbird: released (1:31.1.0+build2-0ubuntu1)