CVE-2015-4482: Buffer Overflow
Published Aug 16, 2015
·Updated
marread.c in the Updater in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows local users to gain privileges or cause a denial of service (out-of-bounds write) via a crafted name of a Mozilla Archive (aka MAR) file.
Affected Software
12 affected components
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Mozilla Firefox<=39.0.3
Mozilla Firefox=38.0
Mozilla Firefox=38.0.1
Mozilla Firefox=38.0.5
Mozilla Firefox=38.1.0
Oracle Solaris=11.3
Mozilla Firefox ESR=38.0
Mozilla Firefox ESR=38.0.1
Mozilla Firefox ESR=38.0.5
Mozilla Firefox ESR=38.1.0
Event History
Aug 16, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4482?
CVE-2015-4482 has a medium severity rating as it allows local users to gain privileges or cause a denial of service.
2
How do I fix CVE-2015-4482?
To fix CVE-2015-4482, update Mozilla Firefox to version 40.0 or later or Firefox ESR to version 38.2 or later.
3
What versions of Mozilla Firefox are affected by CVE-2015-4482?
CVE-2015-4482 affects Mozilla Firefox versions before 40.0 and Firefox ESR versions before 38.2.
4
Can CVE-2015-4482 lead to data loss?
Yes, CVE-2015-4482 can potentially lead to data loss due to the out-of-bounds write vulnerability.
5
Is CVE-2015-4482 a remote or local vulnerability?
CVE-2015-4482 is a local vulnerability that requires local user access to exploit.