First published: Mon Jul 06 2015(Updated: )
Last updated 24 July 2024
Credit: security@mozilla.org security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/icedove | ||
debian/iceweasel | ||
Mozilla Firefox | <=38.1.0 | |
Mozilla Thunderbird | <=38.0.1 | |
Oracle Solaris | =11.3 | |
Mozilla Firefox ESR | =31.0 | |
Mozilla Firefox ESR | =31.1 | |
Mozilla Firefox ESR | =31.1.0 | |
Mozilla Firefox ESR | =31.1.1 | |
Mozilla Firefox ESR | =31.2 | |
Mozilla Firefox ESR | =31.3 | |
Mozilla Firefox ESR | =31.3.0 | |
Mozilla Firefox ESR | =31.4 | |
Mozilla Firefox ESR | =31.5 | |
Mozilla Firefox ESR | =31.5.1 | |
Mozilla Firefox ESR | =31.5.2 | |
Mozilla Firefox ESR | =31.5.3 | |
Mozilla Firefox ESR | =31.6.0 | |
Mozilla Firefox ESR | =31.7.0 | |
Mozilla Firefox ESR | =38.0 | |
Mozilla Firefox | =31.0 | |
Mozilla Firefox | =31.1.0 | |
Mozilla Firefox | =31.1.1 | |
Mozilla Firefox | =31.3.0 | |
Mozilla Firefox | =31.5.1 | |
Mozilla Firefox | =31.5.2 | |
Mozilla Firefox | =31.5.3 | |
Mozilla Firefox | =38.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2731 is a use-after-free vulnerability in the CSPService::ShouldLoad function in Mozilla Firefox and Thunderbird, allowing remote attackers to execute arbitrary code.
CVE-2015-2731 is classified as a critical vulnerability with a severity score of 10.
Mozilla Firefox versions before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird versions before 38.1 are affected by CVE-2015-2731.
To fix CVE-2015-2731, update Mozilla Firefox to version 39.0 or later, Firefox ESR to version 38.1 or later, and Thunderbird to version 38.1 or later.
More information about CVE-2015-2731 can be found on the CVE website at https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2731 and the Mozilla Security Advisories website at https://www.mozilla.org/en-US/security/advisories/mfsa2015-63/.