CVE-2015-2717

Publication date 13 May 2015

Last updated 24 July 2024


Ubuntu priority

Integer overflow in libstagefright in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and out-of-bounds read) via an MP4 video file containing invalid metadata.

Status

Package Ubuntu Release Status
firefox 15.04 vivid
Fixed 38.0+build3-0ubuntu0.15.04.1
14.10 utopic
Fixed 38.0+build3-0ubuntu0.14.10.1
14.04 LTS trusty
Fixed 38.0+build3-0ubuntu0.14.04.1
12.04 LTS precise
Fixed 38.0+build3-0ubuntu0.12.04.1

References

Related Ubuntu Security Notices (USN)

Other references