Information Disclosure Vulnerability in Mozilla Firefox and SeaMonkey
CVE-2014-8637

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
14 January 2015

What is CVE-2014-8637?

Mozilla Firefox prior to version 35.0 and SeaMonkey prior to version 2.32 are susceptible to an information disclosure issue due to improper memory initialization for BMP images. This flaw enables remote attackers to extract sensitive data from the process memory through crafting a malicious web page that exploits the flaw during the rendering of malformed BMP data within a CANVAS element. Users are strongly advised to update their software to mitigate the risks associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.