CVE-2015-2717Out-of-bounds Read in Mozilla Firefox

Severity
6.8MEDIUMNVD
OSV7.5
EPSS
2.4%
top 14.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 14
Latest updateMay 14

Description

Integer overflow in libstagefright in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and out-of-bounds read) via an MP4 video file containing invalid metadata.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

Ubuntumozilla/firefox< 38.0+build3-0ubuntu0.14.04.1
NVDmozilla/firefox37.0.2
NVDopensuse/opensuse13.1, 13.2+1

🔴Vulnerability Details

3
GHSA
GHSA-vp54-5hxv-hg3j: Integer overflow in libstagefright in Mozilla Firefox before 382022-05-14
OSV
firefox vulnerabilities2015-05-13
OSV
CVE-2015-2717: Integer overflow in libstagefright in Mozilla Firefox before 382015-05-13

📋Vendor Advisories

2
Ubuntu
Firefox vulnerabilities2015-05-13
Red Hat
Mozilla: Buffer overflow and out-of-bounds read while parsing MP4 video metadata (MFSA 2015-55)2015-05-12

💬Community

1
Bugzilla
CVE-2015-2717 Mozilla: Buffer overflow and out-of-bounds read while parsing MP4 video metadata (MFSA 2015-55)2015-05-12