CVE Vulnerabilities

CVE-2015-7213

Published: Dec 16, 2015 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
5.1 IMPORTANT
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 on 64-bit platforms allows remote attackers to execute arbitrary code via a crafted MP4 video file that triggers a buffer overflow.

Affected Software

Name Vendor Start Version End Version
Leap Opensuse 42.1 (including) 42.1 (including)
Opensuse Opensuse 13.1 (including) 13.1 (including)
Opensuse Opensuse 13.2 (including) 13.2 (including)
Firefox Ubuntu devel *
Firefox Ubuntu precise *
Firefox Ubuntu trusty *
Firefox Ubuntu upstream *
Firefox Ubuntu vivid *
Firefox Ubuntu wily *
Thunderbird Ubuntu devel *
Thunderbird Ubuntu precise *
Thunderbird Ubuntu trusty *
Thunderbird Ubuntu upstream *
Thunderbird Ubuntu vivid *
Thunderbird Ubuntu wily *
Red Hat Enterprise Linux 5 RedHat firefox-0:38.5.0-2.el5_11 *
Red Hat Enterprise Linux 5 RedHat thunderbird-0:38.5.0-1.el5_11 *
Red Hat Enterprise Linux 6 RedHat firefox-0:38.5.0-2.el6_7 *
Red Hat Enterprise Linux 6 RedHat thunderbird-0:38.5.0-1.el6_7 *
Red Hat Enterprise Linux 7 RedHat firefox-0:38.5.0-3.el7_2 *
Red Hat Enterprise Linux 7 RedHat thunderbird-0:38.5.0-1.el7_2 *

References