Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-3211-1 | iceweasel security update |
Debian DSA |
DSA-3212-1 | icedove security update |
EUVD |
EUVD-2015-0826 | Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file. |
Ubuntu USN |
USN-2550-1 | Firefox vulnerabilities |
Ubuntu USN |
USN-2552-1 | Thunderbird vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-06T04:26:11.047Z
Reserved: 2015-01-07T00:00:00
Link: CVE-2015-0813
No data.
Status : Deferred
Published: 2015-04-01T10:59:12.303
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-0813
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN