CVE-2015-7205Integer Underflow (Wrap or Wraparound) in Mozilla Firefox

CWE-1899 documents6 sources
Severity
10.0CRITICALNVD
EPSS
0.9%
top 24.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 16
Latest updateMay 14

Description

Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 might allow remote attackers to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a crafted WebRTC RTP packet.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages5 packages

Ubuntumozilla/firefox< 43.0+build1-0ubuntu0.14.04.1
NVDmozilla/firefox42.0+9
Ubuntumozilla/thunderbird< 1:38.5.1+build2-0ubuntu0.14.04.1
NVDopensuse/leap42.1
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Fedora 22, 23

🔴Vulnerability Details

4
GHSA
GHSA-cwgv-fxx6-cp78: Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in Mozilla Firefox before 432022-05-14
OSV
thunderbird vulnerabilities2016-01-13
OSV
CVE-2015-7205: Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in Mozilla Firefox before 432015-12-15
OSV
firefox vulnerabilities2015-12-15

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2016-01-13
Red Hat
Mozilla: Underflow through code inspection (MFSA 2015-145)2015-12-16
Ubuntu
Firefox vulnerabilities2015-12-15

💬Community

1
Bugzilla
CVE-2015-7205 Mozilla: Underflow through code inspection (MFSA 2015-145)2015-12-15
CVE-2015-7205 — Integer Underflow (Wrap or Wraparound) | cvebase