PT-2015-2166 · Mozilla+3 · Qcms+4

Groebert

·

Publicado

2015-09-22

·

Atualizado

2024-12-12

·

CVE-2015-4504

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 41.0
Description The issue is caused by a buffer overflow in the lut inverse interp16 function of the QCMS library. This can be exploited by a remote attacker using a specially crafted image, potentially allowing access to sensitive information or causing a denial of service, including a buffer over-read and application crash.
Recommendations For versions prior to 41.0, update to version 41.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of images with manipulated ICC 4 profiles until the update is applied.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1816
ALT-PU-2016-1454
BDU:2015-11512
CVE-2015-4504
MGASA-2015-0414
OPENSUSE-SU-2015_1658-1
OPENSUSE-SU-2015_1681-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
USN-2743-1
USN-2743-2
USN-2743-3
USN-2743-4

Produtos afetados

Alt Linux
Firefox
Qcms
Suse
Ubuntu