The package firefox before version 35.0-1 is vulnerable to multiple issues, including but not limited to remote code execution.
Arch Linux Security Advisory ASA-201501-6
========================================
Severity: Critical
Date : 2015-01-14
CVE-ID : CVE-2014-8634 CVE-2014-8635 CVE-2014-8636 CVE-2014-8637
CVE-2014-8638 CVE-2014-8639 CVE-2014-8640 CVE-2014-8641 CVE-2014-8642
Package : firefox
Type : multiple issues
Remote : Yes
Link : https://wiki.archlinux.org/title/CVE
Summary
======
The package firefox before version 35.0-1 is vulnerable to multiple
issues, including but not limited to remote code execution.
Resolution
=========
Upgrade to 35.0-1.
# pacman -Syu "firefox>=35.0-1"
The problem has been fixed upstream in version 35.0.
Workaround
=========
None.
Description
==========
- CVE-2014-8634 (arbitrary remote code execution)
Christian Holler and Patrick McManus reported memory safety problems and
crashes that affect Firefox ESR 31.3 and Firefox 34.
- CVE-2014-8635 (arbitrary remote code execution)
Christoph Diehl, Christian Holler, Gary Kwong, Jesse Ruderman, Byron
Campen, Terrence Cole, and Nils Ohlmeier reported memory safety problems
and crashes that affect Firefox 34.
- CVE-2014-8636 (arbitrary javascript code execution, privilege escalation)
Mozilla developer Bobby Holley reported that Document Object Model (DOM)
objects with some specific properties can bypass XrayWrappers. This can
allow web content to confuse privileged code, potentially enabling
privilege escalation.
- CVE-2014-8637 (information leakage)
Google security researcher Michal Zalewski reported that when a
malformed bitmap image is rendered by the bitmap decoder within a