PT-2016-1251 · Mozilla+4 · Firefox+4
Q1
·
Publicado
2016-01-26
·
Atualizado
2024-06-15
·
CVE-2016-1946
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 44.0
Description
The issue is related to the MoofParser::Metadata function in libstagefright, which does not limit the size of read operations. This might allow remote attackers to cause a denial of service due to an integer overflow and buffer overflow, or possibly have other unspecified impacts via crafted metadata. The vulnerability is associated with a buffer overflow in dynamic memory caused by an integer overflow.
Recommendations
For versions prior to 44.0, update to version 44.0 or later to resolve the issue. As a temporary workaround, consider restricting access to crafted metadata to minimize the risk of exploitation.
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Firefox
Suse
Ubuntu
Libstagefright