The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a malformed file.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
History
                    21 Nov 2024, 02:31
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.html - | |
| References | () http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.html - | |
| References | () http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.html - | |
| References | () http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00016.html - | |
| References | () http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html - | |
| References | () http://lists.opensuse.org/opensuse-updates/2015-08/msg00030.html - | |
| References | () http://lists.opensuse.org/opensuse-updates/2015-08/msg00031.html - | |
| References | () http://rhn.redhat.com/errata/RHSA-2015-1586.html - | |
| References | () http://www.mozilla.org/security/announce/2015/mfsa2015-80.html - Vendor Advisory | |
| References | () http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html - | |
| References | () http://www.securityfocus.com/bid/76294 - | |
| References | () http://www.securitytracker.com/id/1033247 - | |
| References | () http://www.ubuntu.com/usn/USN-2702-1 - | |
| References | () http://www.ubuntu.com/usn/USN-2702-2 - | |
| References | () http://www.ubuntu.com/usn/USN-2702-3 - | |
| References | () https://bugzilla.mozilla.org/show_bug.cgi?id=1175396 - | |
| References | () https://security.gentoo.org/glsa/201605-06 - | 
22 Oct 2024, 13:42
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:mozilla:firefox_esr:38.1.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:38.0.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:* | cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.0.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.0.5:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.1.0:*:*:*:*:*:*:* | 
Information
                Published : 2015-08-16 01:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-4475
Mitre link : CVE-2015-4475
CVE.ORG link : CVE-2015-4475
JSON object : View
Products Affected
                opensuse
- opensuse
canonical
- ubuntu_linux
mozilla
- firefox
CWE
                
                    
                        
                        CWE-119
                        
            Improper Restriction of Operations within the Bounds of a Memory Buffer
