Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-1968

Опубликовано: 13 мар. 2016
Источник: debian
EPSS Низкий

Описание

Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted data with brotli compression.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
iceweaselremovedpackage
iceweaselnot-affectedjessiepackage
iceweaselnot-affectedwheezypackage
firefox-esrfixed45.0esr-1package
firefoxfixed45.0-1package
brotlifixed0.3.0+dfsg-3package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2016-30/

  • https://github.com/google/brotli/commit/37a320dd81db8d546cd24a45b4c61d87b45dcade

EPSS

Процентиль: 82%
0.01806
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 10 лет назад

Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted data with brotli compression.

redhat
почти 10 лет назад

Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted data with brotli compression.

CVSS3: 8.8
nvd
почти 10 лет назад

Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted data with brotli compression.

CVSS3: 8.8
github
больше 3 лет назад

Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted data with brotli compression.

fstec
почти 10 лет назад

Уязвимость браузера Firefox, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

EPSS

Процентиль: 82%
0.01806
Низкий