FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2014-1543

This CVE name corresponds to:

Entered Topic
2014-06-10 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2014-1543
Phase Assigned(20140116)

Description

Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API in Mozilla Firefox before 30.0 allow remote attackers to execute arbitrary code by using non-contiguous axes with a (1) physical or (2) virtual Gamepad device.

References

Source Reference
CONFIRM http://www.mozilla.org/security/announce/2014/mfsa2014-54.html
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=1011859
SUSE openSUSE-SU-2014:0855
BID 67969
SECTRACK 1030388
SECUNIA 59171
SECUNIA 59866
SECUNIA 59387