CVE-2014-1507

Publication date

2014-03-19 10:00:00

Family

mozilla

State

PUBLISHED

Description

Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted application that uses a relative pathname for a DeviceStorageFile object.