First published: Sun Aug 16 2015(Updated: )
The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Solaris SPARC | =11.3 | |
Mozilla Firefox | <=39.0.3 | |
Mozilla Firefox | =38.0 | |
Mozilla Firefox | =38.0.1 | |
Mozilla Firefox | =38.0.5 | |
Mozilla Firefox | =38.1.0 | |
Mozilla Firefox OS | <=2.1.0 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =15.04 | |
openSUSE | =13.1 | |
openSUSE | =13.2 | |
Mozilla Firefox ESR | =38.0 | |
Mozilla Firefox ESR | =38.0.1 | |
Mozilla Firefox ESR | =38.0.5 | |
Mozilla Firefox ESR | =38.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4489 is classified with a severity that can lead to denial of service due to memory corruption.
To fix CVE-2015-4489, ensure that you update your Firefox or Firefox ESR to a version later than 40.0 or 38.2 respectively.
CVE-2015-4489 affects Mozilla Firefox versions before 40.0 and Firefox ESR 38.x versions before 38.2.
Yes, CVE-2015-4489 also affects Firefox OS versions before 2.2.
CVE-2015-4489 can allow remote attackers to cause a denial of service and potentially other unspecified impacts.