CVE-2015-4493: Buffer Overflow
Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via an invalid size field in an esds chunk in MPEG-4 video data, a related issue to CVE-2015-1539.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4493?
CVE-2015-4493 is considered critical due to its potential to allow remote code execution.
How do I fix CVE-2015-4493?
To fix CVE-2015-4493, update Mozilla Firefox to version 40.0 or later, or Firefox ESR to version 38.2 or later.
What versions of Firefox are affected by CVE-2015-4493?
CVE-2015-4493 affects Firefox versions prior to 40.0 and Firefox ESR versions prior to 38.2.
Can CVE-2015-4493 be exploited remotely?
Yes, CVE-2015-4493 can be exploited remotely through crafted MPEG-4 video data.
What types of systems are vulnerable to CVE-2015-4493?
CVE-2015-4493 primarily affects users on Firefox and Firefox ESR running on various operating systems including Oracle Solaris and Ubuntu.