CVE-2015-4496: Integer Overflow
Published Aug 16, 2015
·Updated
Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.
Affected Software
2 affected components
Oracle Solaris=11.3
Mozilla Firefox<=37.0.2
Event History
Aug 16, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4496?
CVE-2015-4496 has a critical severity rating due to potential for remote code execution.
2
How do I fix CVE-2015-4496?
To fix CVE-2015-4496, update Mozilla Firefox to version 38.0 or later.
3
Which versions of Firefox are affected by CVE-2015-4496?
CVE-2015-4496 affects Mozilla Firefox versions prior to 38.0.
4
Does CVE-2015-4496 affect Oracle Solaris?
Yes, CVE-2015-4496 affects Oracle Solaris 11.3 in conjunction with the vulnerable Firefox versions.
5
What types of attacks are possible with CVE-2015-4496?
CVE-2015-4496 allows remote attackers to execute arbitrary code via specially crafted MPEG-4 video files.