GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-2164-1 | gst-plugins-bad0.10 security update |
![]() |
DSA-3225-1 | gst-plugins-bad0.10 security update |
![]() |
DSA-3260-1 | iceweasel security update |
![]() |
DSA-3264-1 | icedove security update |
![]() |
EUVD-2015-0810 | GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 22 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | ||
Vendors & Products |
Mozilla firefox Esr
|

Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-06T04:26:10.193Z
Reserved: 2015-01-07T00:00:00
Link: CVE-2015-0797

No data.

Status : Deferred
Published: 2015-05-14T10:59:00.070
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-0797


No data.