CVE-2015-1207
published 2017-06-06CVE-2015-1207: Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption…
PriorityP423medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
0.84%
54.0th percentile
Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | ffmpeg | < ffmpeg 7:2.6.1-1 (bookworm) | ffmpeg 7:2.6.1-1 (bookworm) |
| ffmpeg | ffmpeg | >= 0 < 7:2.6.1-1 | 7:2.6.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.6.1-1 | 7:2.6.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.6.1-1 | 7:2.6.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.6.1-1 | 7:2.6.1-1 |
| chrome | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2015-1207: ffmpeg - Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2...
vendor_debian·2015·CVSS 6.5
CVE-2015-1207 [MEDIUM] CVE-2015-1207: ffmpeg - Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2...
Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.
Scope: local
bookworm: resolved (fixed in 7:2.6.1-1)
bullseye: resolved (fixed in 7:2.6.1-1)
forky: resolved (fixed in 7:2.6.1-1)
sid: resolved (fixed in 7:2.6.1-1)
trixie: resolved (fixed in 7:2.6.1-1)
GHSA
GHSA-xhm7-3cgh-g3g7: Double-free vulnerability in libavformat/mov
ghsa_unreviewed·2022-05-14
CVE-2015-1207 [MEDIUM] CWE-415 GHSA-xhm7-3cgh-g3g7: Double-free vulnerability in libavformat/mov
Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.
OSV
CVE-2015-1207: Double-free vulnerability in libavformat/mov
osv·2017-06-06·CVSS 6.5
CVE-2015-1207 [MEDIUM] CVE-2015-1207: Double-free vulnerability in libavformat/mov
Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2728 Mozilla: Type confusion in Indexed Database Manager (MFSA 2015-61)
bugzilla·2015-06-30·CVSS 7.5
CVE-2015-2728 [HIGH] CVE-2015-2728 Mozilla: Type confusion in Indexed Database Manager (MFSA 2015-61)
CVE-2015-2728 Mozilla: Type confusion in Indexed Database Manager (MFSA 2015-61)
Security researcher Paul Bandha reported a type confusion error where part of IDBDatabase is read by the Indexed Database Manager and incorrectly used as a pointer when it shouldn't be used as such. This leads to memory corruption and the possibility of an exploitable crash.
External Reference:
http://www.mozilla.org/security/announce/2015/mfsa2015-61.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Paul Bandha as the original reporter.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2015:1207 https://rhn.redhat.com/errat
Bugzilla
CVE-2015-2729 Mozilla: Out-of-bound read while computing an oscillator rendering range in Web Audio (MFSA 2015-62)
bugzilla·2015-06-30·CVSS 5.0
CVE-2015-2729 [MEDIUM] CVE-2015-2729 Mozilla: Out-of-bound read while computing an oscillator rendering range in Web Audio (MFSA 2015-62)
CVE-2015-2729 Mozilla: Out-of-bound read while computing an oscillator rendering range in Web Audio (MFSA 2015-62)
Security researcher Holger Fuhrmannek used the Address Sanitizer tool to discover an out-of-bound read while computing an oscillator rendering range in Web Audio. This could allow an attacker to infer the contents of four bytes of memory.
External Reference:
http://www.mozilla.org/security/announce/2015/mfsa2015-62.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Holger Fuhrmannek as the original reporter.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2015:1207 https://rhn.redhat.com/er
https://bugs.chromium.org/p/chromium/issues/detail?id=444539https://gist.github.com/bittorrent3389/8fee7cdaa73d1d351ee9https://lists.debian.org/debian-lts-announce/2019/02/msg00005.htmlhttps://bugs.chromium.org/p/chromium/issues/detail?id=444539https://gist.github.com/bittorrent3389/8fee7cdaa73d1d351ee9https://lists.debian.org/debian-lts-announce/2019/02/msg00005.html
2017-06-06
Published