First published: Sun Aug 16 2015(Updated: )
Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Solaris and Zettabyte File System (ZFS) | =11.3 | |
Firefox | <=37.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4496 has a critical severity rating due to potential for remote code execution.
To fix CVE-2015-4496, update Mozilla Firefox to version 38.0 or later.
CVE-2015-4496 affects Mozilla Firefox versions prior to 38.0.
Yes, CVE-2015-4496 affects Oracle Solaris 11.3 in conjunction with the vulnerable Firefox versions.
CVE-2015-4496 allows remote attackers to execute arbitrary code via specially crafted MPEG-4 video files.