CVE-2015-4480: Integer Overflow
Integer overflow in the stagefright::SampleTable::isValid function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via crafted MPEG-4 video data with H.264 encoding.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4480?
CVE-2015-4480 is classified as a high-severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2015-4480?
To fix CVE-2015-4480, update Mozilla Firefox to version 40.0 or later, or Firefox ESR to version 38.2 or later.
What types of systems are affected by CVE-2015-4480?
CVE-2015-4480 affects specific versions of Ubuntu Linux from 12.04 to 15.04 and openSUSE versions 13.1 and 13.2.
How does CVE-2015-4480 exploit vulnerabilities?
CVE-2015-4480 exploits an integer overflow in the libstagefright component, allowing remote attackers to execute arbitrary code via crafted MPEG-4 video data.
What versions of Mozilla Firefox are impacted by CVE-2015-4480?
CVE-2015-4480 impacts Mozilla Firefox versions prior to 40.0 and Firefox ESR versions prior to 38.2.