~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2014-8640

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2015-01-14
2
 
Candidate: CVE-2014-8640
3
 
PublicDate: 2015-01-14
4
 
References: 
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8640
6
 
 https://www.mozilla.org/en-GB/security/advisories/mfsa2015-05/
7
 
 https://usn.ubuntu.com/usn/usn-2458-1
8
 
Description:
9
 
 The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the
10
 
 Web Audio API implementation in Mozilla Firefox before 35.0 and SeaMonkey
11
 
 before 2.32 does not properly restrict timeline operations, which allows
12
 
 remote attackers to cause a denial of service (uninitialized-memory read
13
 
 and application crash) via crafted API calls.
14
 
Ubuntu-Description: 
15
 
Notes: 
16
 
Bugs: 
17
 
Priority: medium
18
 
Discovered-by:
19
 
Assigned-to: chrisccoulson
20
 
 
21
 
Patches_firefox: 
22
 
upstream_firefox: released (35.0)
23
 
lucid_firefox: ignored (reached end of life)
24
 
precise_firefox: released (35.0+build3-0ubuntu0.12.04.2)
25
 
trusty_firefox: released (35.0+build3-0ubuntu0.14.04.2)
26
 
utopic_firefox: released (35.0+build3-0ubuntu0.14.10.2)
27
 
devel_firefox: released (35.0+build3-0ubuntu1)