CVE-2015-4475

The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a malformed file.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.html
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.html
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.html
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00016.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html
http://lists.opensuse.org/opensuse-updates/2015-08/msg00030.html
http://lists.opensuse.org/opensuse-updates/2015-08/msg00031.html
http://rhn.redhat.com/errata/RHSA-2015-1586.html
http://www.mozilla.org/security/announce/2015/mfsa2015-80.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.securityfocus.com/bid/76294
http://www.securitytracker.com/id/1033247
http://www.ubuntu.com/usn/USN-2702-1
http://www.ubuntu.com/usn/USN-2702-2
http://www.ubuntu.com/usn/USN-2702-3
https://bugzilla.mozilla.org/show_bug.cgi?id=1175396
https://security.gentoo.org/glsa/201605-06
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.html
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.html
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.html
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00016.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html
http://lists.opensuse.org/opensuse-updates/2015-08/msg00030.html
http://lists.opensuse.org/opensuse-updates/2015-08/msg00031.html
http://rhn.redhat.com/errata/RHSA-2015-1586.html
http://www.mozilla.org/security/announce/2015/mfsa2015-80.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.securityfocus.com/bid/76294
http://www.securitytracker.com/id/1033247
http://www.ubuntu.com/usn/USN-2702-1
http://www.ubuntu.com/usn/USN-2702-2
http://www.ubuntu.com/usn/USN-2702-3
https://bugzilla.mozilla.org/show_bug.cgi?id=1175396
https://security.gentoo.org/glsa/201605-06
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.1.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*

History

21 Nov 2024, 02:31

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.html - () http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.html -
References () http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.html - () http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.html -
References () http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.html - () http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.html -
References () http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00016.html - () http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00016.html -
References () http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html - () http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html -
References () http://lists.opensuse.org/opensuse-updates/2015-08/msg00030.html - () http://lists.opensuse.org/opensuse-updates/2015-08/msg00030.html -
References () http://lists.opensuse.org/opensuse-updates/2015-08/msg00031.html - () http://lists.opensuse.org/opensuse-updates/2015-08/msg00031.html -
References () http://rhn.redhat.com/errata/RHSA-2015-1586.html - () http://rhn.redhat.com/errata/RHSA-2015-1586.html -
References () http://www.mozilla.org/security/announce/2015/mfsa2015-80.html - Vendor Advisory () http://www.mozilla.org/security/announce/2015/mfsa2015-80.html - Vendor Advisory
References () http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html - () http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html -
References () http://www.securityfocus.com/bid/76294 - () http://www.securityfocus.com/bid/76294 -
References () http://www.securitytracker.com/id/1033247 - () http://www.securitytracker.com/id/1033247 -
References () http://www.ubuntu.com/usn/USN-2702-1 - () http://www.ubuntu.com/usn/USN-2702-1 -
References () http://www.ubuntu.com/usn/USN-2702-2 - () http://www.ubuntu.com/usn/USN-2702-2 -
References () http://www.ubuntu.com/usn/USN-2702-3 - () http://www.ubuntu.com/usn/USN-2702-3 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1175396 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1175396 -
References () https://security.gentoo.org/glsa/201605-06 - () https://security.gentoo.org/glsa/201605-06 -

22 Oct 2024, 13:42

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox_esr:38.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.1.0:*:*:*:*:*:*:*

Information

Published : 2015-08-16 01:59

Updated : 2025-04-12 10:46


NVD link : CVE-2015-4475

Mitre link : CVE-2015-4475

CVE.ORG link : CVE-2015-4475


JSON object : View

Products Affected

opensuse

  • opensuse

canonical

  • ubuntu_linux

mozilla

  • firefox
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer