Mozilla Firefox/Thunderbird Multiple Memory Corruption Vulnerabilities (CVE-2014-1562)
Released on: 2014-09-02
Updated on: 2014-09-04
Affected Systems:
Mozilla Firefox
Mozilla Thunderbird
Description:
--------------------------------------------------------------------------------
Bugtraq id: 69519
CVE (CAN) ID: CVE-2014-1562
Firefox/Thunderbird/SeaMonkey is the WEB browser and mail/newsgroup client released by Mozilla.
Mozilla Firefox and Thunderbird have multiple memory security issues. If attackers trick users into opening constructed websites, these vulnerabilities can be exploited to cause application crash, this causes a denial of service or arbitrary code execution with the current user permission.
<* Source: Jan de Mooij
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Mozilla
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.mozilla.org/security/
For more information about Thunderbird, click here.
Thunderbird: click here
Red Hat Enterprise 6.3 manual installation of Thunderbird
Use apt-get to install FireFox and ThunderBird In Debian Linux
Ubuntu's Guide to Using Thunderbird [graphic]
Install Thunderbird 3 and Chinese display settings on Ubuntu
Use Evolution and Thunderbird to send and receive emails in Ubuntu
This article permanently updates the link address: