Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-7222

Опубликовано: 16 дек. 2015
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8

Описание

Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect memory allocation and application crash) via an MP4 video file with crafted covr metadata that triggers a buffer overflow.

РелизСтатусПримечание
devel

released

43.0+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [43.0+build1-0ubuntu0.14.04.1]]
precise

released

43.0+build1-0ubuntu0.12.04.1
trusty

released

43.0+build1-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [43.0+build1-0ubuntu0.14.04.1]
upstream

released

43.0
vivid

released

43.0+build1-0ubuntu0.15.04.1
wily

released

43.0+build1-0ubuntu0.15.10.1

Показывать по

6.8 Medium

CVSS2

Связанные уязвимости

redhat
больше 9 лет назад

Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect memory allocation and application crash) via an MP4 video file with crafted covr metadata that triggers a buffer overflow.

nvd
больше 9 лет назад

Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect memory allocation and application crash) via an MP4 video file with crafted covr metadata that triggers a buffer overflow.

debian
больше 9 лет назад

Integer underflow in the Metadata::setData function in MetaData.cpp in ...

github
около 3 лет назад

Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect memory allocation and application crash) via an MP4 video file with crafted covr metadata that triggers a buffer overflow.

fstec
больше 9 лет назад

Уязвимость браузеров Firefox и Firefox ESR, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

6.8 Medium

CVSS2