PT-2015-2879 · Mozilla+2 · Firefox+2

Gustavo Grieco

·

Published

2015-12-15

·

Updated

2024-12-12

·

CVE-2015-7216

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 43.0
Description The issue exists due to insufficient input validation in the gdk-pixbuf library structure of the browser. Exploitation of this issue may allow a remote attacker to cause a denial of service or possibly have other impacts by using a specially crafted JPEG 2000 image. The gdk-pixbuf configuration incorrectly enables the JasPer decoder.
Recommendations For versions prior to 43.0, update to version 43.0 or later to resolve the issue. As a temporary workaround, consider disabling the use of the JasPer decoder for JPEG 2000 images until a patch is available. Restrict access to specially crafted JPEG 2000 images to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-12245
CVE-2015-7216
MGASA-2016-0124
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
USN-2833-1

Affected Products

Firefox
Ubuntu
Gdk-Pixbuf