PT-2015-2879 · Mozilla+2 · Firefox+2
Gustavo Grieco
·
Published
2015-12-15
·
Updated
2024-12-12
·
CVE-2015-7216
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 43.0
Description
The issue exists due to insufficient input validation in the gdk-pixbuf library structure of the browser. Exploitation of this issue may allow a remote attacker to cause a denial of service or possibly have other impacts by using a specially crafted JPEG 2000 image. The gdk-pixbuf configuration incorrectly enables the JasPer decoder.
Recommendations
For versions prior to 43.0, update to version 43.0 or later to resolve the issue. As a temporary workaround, consider disabling the use of the JasPer decoder for JPEG 2000 images until a patch is available. Restrict access to specially crafted JPEG 2000 images to minimize the risk of exploitation.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox
Ubuntu
Gdk-Pixbuf