CVE Vulnerabilities

CVE-2015-0797

Published: May 14, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file.

Affected Software

NameVendorStart VersionEnd Version
GstreamerGstreamer_project*1.4.5 (excluding)
FirefoxMozilla*38.0 (excluding)
FirefoxMozilla31.0 (including)31.7 (excluding)
SeamonkeyMozilla*2.35 (excluding)
ThunderbirdMozilla*31.7 (excluding)
ThunderbirdMozilla38.0 (including)38.0.1 (excluding)
Red Hat Enterprise Linux 5RedHatfirefox-0:38.0-4.el5_11*
Red Hat Enterprise Linux 6RedHatfirefox-0:38.0-4.el6_6*
Red Hat Enterprise Linux 7RedHatfirefox-0:38.0-3.ael7b_1*
Gst-plugins-bad0.10Ubuntudevel*
Gst-plugins-bad0.10Ubuntuesm-infra-legacy/trusty*
Gst-plugins-bad0.10Ubuntulucid*
Gst-plugins-bad0.10Ubuntuprecise*
Gst-plugins-bad0.10Ubuntutrusty*
Gst-plugins-bad0.10Ubuntutrusty/esm*
Gst-plugins-bad0.10Ubuntuutopic*

References