7.5
CVSSv2

CVE-2015-4475

Published: 16/08/2015 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The mozilla::AudioSink function in Mozilla Firefox prior to 40.0 and Firefox ESR 38.x prior to 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote malicious users to execute arbitrary code or cause a denial of service (out-of-bounds read) via a malformed file.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox esr 38.0.1

mozilla firefox esr 38.0.5

mozilla firefox esr 38.1.0

mozilla firefox

mozilla firefox esr 38.0

canonical ubuntu linux 15.04

opensuse opensuse 13.1

opensuse opensuse 13.2

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

Vendor Advisories

This update provides compatible packages for Firefox 40 ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
USN-2702-1 introduced a regression in Firefox ...
Mozilla Foundation Security Advisory 2015-80 Out-of-bounds read with malformed MP3 file Announced August 11, 2015 Reporter Aki Helin Impact High Products Firefox, Firefox ESR, Firefox OS, SeaMonkey Fixed in ...