CVE Vulnerabilities

CVE-2015-0813

Published: Apr 01, 2015 | Modified: Jan 03, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 CRITICAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 36.0.4 (including)
Firefox_esr Mozilla * 31.5.3 (including)
Thunderbird Mozilla * 31.5 (including)
Red Hat Enterprise Linux 5 RedHat firefox-0:31.6.0-2.el5_11 *
Red Hat Enterprise Linux 5 RedHat thunderbird-0:31.6.0-1.el5_11 *
Red Hat Enterprise Linux 6 RedHat firefox-0:31.6.0-2.el6_6 *
Red Hat Enterprise Linux 6 RedHat thunderbird-0:31.6.0-1.el6_6 *
Red Hat Enterprise Linux 7 RedHat firefox-0:31.6.0-2.el7_1 *
Red Hat Enterprise Linux 7 RedHat xulrunner-0:31.6.0-2.ael7b_1 *
Red Hat Enterprise Linux 7 RedHat thunderbird-0:31.6.0-1.el7_1 *
Firefox Ubuntu devel *
Firefox Ubuntu lucid *
Firefox Ubuntu precise *
Firefox Ubuntu trusty *
Firefox Ubuntu upstream *
Firefox Ubuntu utopic *
Thunderbird Ubuntu devel *
Thunderbird Ubuntu lucid *
Thunderbird Ubuntu precise *
Thunderbird Ubuntu trusty *
Thunderbird Ubuntu upstream *
Thunderbird Ubuntu utopic *

References