Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via an invalid size field in an esds chunk in MPEG-4 video data, a related issue to CVE-2015-1539.
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.html
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.html
http://lists.opensuse.org/opensuse-updates/2015-08/msg00030.html
http://lists.opensuse.org/opensuse-updates/2015-08/msg00031.html
http://rhn.redhat.com/errata/RHSA-2015-1586.html
http://www.debian.org/security/2015/dsa-3333
http://www.mozilla.org/security/announce/2015/mfsa2015-83.html
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.securitytracker.com/id/1033247
http://www.ubuntu.com/usn/USN-2702-1
http://www.ubuntu.com/usn/USN-2702-2
http://www.ubuntu.com/usn/USN-2702-3
https://bugzilla.mozilla.org/show_bug.cgi?id=1186718
OR
OR
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* versions up to 39.0.3 (inclusive)
cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.0.1:*:*:*:*:*:*:*
OR
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
91379 | GLSA-201605-06 : Mozilla Products: Multiple vulnerabilities (Logjam) (SLOTH) | Nessus | Gentoo Local Security Checks | critical |
8856 | Mozilla Firefox < 40.0 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
85703 | openSUSE Security Update : MozillaThunderbird (openSUSE-2015-559) | Nessus | SuSE Local Security Checks | critical |
85702 | openSUSE Security Update : MozillaThunderbird (openSUSE-2015-558) | Nessus | SuSE Local Security Checks | critical |
85578 | Ubuntu 12.04 LTS / 14.04 LTS / 15.04 : firefox regression (USN-2702-3) | Nessus | Ubuntu Local Security Checks | critical |
85437 | openSUSE Security Update : MozillaFirefox (openSUSE-2015-548) | Nessus | SuSE Local Security Checks | critical |
85436 | openSUSE Security Update : MozillaFirefox (openSUSE-2015-547) | Nessus | SuSE Local Security Checks | critical |
85386 | Firefox < 40 Multiple Vulnerabilities | Nessus | Windows | critical |
85385 | Firefox ESR < 38.2 Multiple Vulnerabilities | Nessus | Windows | critical |
85384 | Firefox < 40 Multiple Vulnerabilities (Mac OS X) | Nessus | MacOS X Local Security Checks | critical |
85383 | Firefox ESR < 38.2 Multiple Vulnerabilities (Mac OS X) | Nessus | MacOS X Local Security Checks | critical |
85356 | Debian DSA-3333-1 : iceweasel - security update | Nessus | Debian Local Security Checks | critical |
85345 | Ubuntu 12.04 LTS / 14.04 LTS / 15.04 : ubufox update (USN-2702-2) | Nessus | Ubuntu Local Security Checks | critical |
85344 | Ubuntu 12.04 LTS / 14.04 LTS / 15.04 : firefox vulnerabilities (USN-2702-1) | Nessus | Ubuntu Local Security Checks | critical |
85343 | Scientific Linux Security Update : firefox on SL5.x, SL6.x, SL7.x i386/x86_64 (20150811) | Nessus | Scientific Linux Local Security Checks | critical |
85342 | RHEL 5 / 6 / 7 : firefox (RHSA-2015:1586) | Nessus | Red Hat Local Security Checks | critical |
85339 | Oracle Linux 5 / 6 / 7 : firefox (ELSA-2015-1586) | Nessus | Oracle Linux Local Security Checks | critical |
85338 | FreeBSD : mozilla -- multiple vulnerabilities (c66a5632-708a-4727-8236-d65b2d5b2739) | Nessus | FreeBSD Local Security Checks | critical |
85336 | CentOS 5 / 6 / 7 : firefox (CESA-2015:1586) | Nessus | CentOS Local Security Checks | critical |