PT-2015-1042 · Mozilla+3 · Firefox+3
Mitchwharper
·
Publicado
2015-03-31
·
Atualizado
2024-12-12
·
CVE-2015-0808
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 37.0
Description
The issue is related to the webrtc::VPMContentAnalysis::Release function in the WebRTC implementation, which uses incompatible methods for deallocating memory allocated for simple-type arrays. This could allow a remote attacker to cause a denial of service, potentially resulting in memory corruption.
Recommendations
For versions prior to 37.0, update to version 37.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of WebRTC functionality until the update is applied.
Exploit
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Firefox
Suse
Ubuntu