The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a malformed file.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
Configuration 2 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2015-08-16 01:59
Updated : 2018-10-30 16:27
NVD link : CVE-2015-4475
Mitre link : CVE-2015-4475
CVE.ORG link : CVE-2015-4475
JSON object : View
Products Affected
                opensuse
- opensuse
 
canonical
- ubuntu_linux
 
mozilla
- firefox
 - firefox_esr
 
CWE
                
                    
                        
                        CWE-119
                        
            Improper Restriction of Operations within the Bounds of a Memory Buffer
