Buffer overflows found through code inspection

Related Vulnerabilities: CVE-2015-7203   CVE-2015-7220   CVE-2015-7221  

Mozilla Foundation Security Advisory 2015-144

Buffer overflows found through code inspection

Announced
December 15, 2015
Reporter
Ronald Crane
Impact
Moderate
Products
Firefox
Fixed in
  • Firefox 43

Description

Security researcher Ronald Crane reported three buffer overflows affecting released code that were found through code inspection. They do not all have clear mechanisms to be exploited through web content but are vulnerable if a mechanism can be found to trigger them.

References