PT-2016-1251 · Mozilla+4 · Firefox+4

Q1

·

Publicado

2016-01-26

·

Atualizado

2024-06-15

·

CVE-2016-1946

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 44.0
Description The issue is related to the MoofParser::Metadata function in libstagefright, which does not limit the size of read operations. This might allow remote attackers to cause a denial of service due to an integer overflow and buffer overflow, or possibly have other unspecified impacts via crafted metadata. The vulnerability is associated with a buffer overflow in dynamic memory caused by an integer overflow.
Recommendations For versions prior to 44.0, update to version 44.0 or later to resolve the issue. As a temporary workaround, consider restricting access to crafted metadata to minimize the risk of exploitation.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1057
ALT-PU-2016-1454
BDU:2016-00512
CVE-2016-1946
OPENSUSE-SU-2016_0309-1
OPENSUSE-SU-2024:10071-1
USN-2880-1
USN-2880-2

Produtos afetados

Alt Linux
Firefox
Suse
Ubuntu
Libstagefright