Red Hat Bugzilla – Bug 1107423
CVE-2014-1540 Mozilla: Use-after-free in Event Listener Manager (MFSA 2014-51)
Last modified: 2016-03-04 07:55:22 EST
Security researchers Tyson Smith and Jesse Schwartzentruber of the BlackBerry Security Automated Analysis Team used the Address Sanitizer tool while fuzzing to discover a use-after-free in the event listener manager. This can be triggered by web content and leads to a potentially exploitable crash. This issue was introduced in Firefox 29 and does not affect earlier versions. External Reference: http://www.mozilla.org/security/announce/2014/mfsa2014-51.html Acknowledgements: Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Tyson Smith and Jesse Schwartzentruber as the original reporter. Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6