CVE Vulnerabilities

CVE-2015-0797

Published: May 14, 2015 | Modified: Mar 17, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file.

Affected Software

NameVendorStart VersionEnd Version
GstreamerGstreamer*1.4.5 (excluding)
FirefoxMozilla*38.0 (excluding)
FirefoxMozilla31.0 (including)31.7 (excluding)
SeamonkeyMozilla*2.35 (excluding)
ThunderbirdMozilla*31.7 (excluding)
ThunderbirdMozilla38.0 (including)38.0.1 (excluding)
Red Hat Enterprise Linux 5RedHatfirefox-0:38.0-4.el5_11*
Red Hat Enterprise Linux 6RedHatfirefox-0:38.0-4.el6_6*
Red Hat Enterprise Linux 7RedHatfirefox-0:38.0-3.ael7b_1*
Gst-plugins-bad0.10Ubuntudevel*
Gst-plugins-bad0.10Ubuntuesm-infra-legacy/trusty*
Gst-plugins-bad0.10Ubuntulucid*
Gst-plugins-bad0.10Ubuntuprecise*
Gst-plugins-bad0.10Ubuntutrusty*
Gst-plugins-bad0.10Ubuntutrusty/esm*
Gst-plugins-bad0.10Ubuntuutopic*

References