CVE-2015-4511: Buffer Overflow
Published Sep 24, 2015
·Updated
Heap-based buffer overflow in the nesteggtrackcodecdata function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via a crafted header in a WebM video.
Affected Software
15 affected components
Mozilla Firefox=38.0
Mozilla Firefox=38.0.1
Mozilla Firefox=38.0.5
Mozilla Firefox=38.1.0
Mozilla Firefox=38.1.1
Mozilla Firefox=38.2.0
Mozilla Firefox=38.2.1
Mozilla Firefox<=40.0.3
Mozilla Firefox ESR=38.0
Mozilla Firefox ESR=38.0.1
Mozilla Firefox ESR=38.0.5
Mozilla Firefox ESR=38.1.0
Mozilla Firefox ESR=38.1.1
Mozilla Firefox ESR=38.2.0
Mozilla Firefox ESR=38.2.1
Event History
Sep 24, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4511?
CVE-2015-4511 has a high severity as it can lead to remote code execution due to a heap-based buffer overflow.
2
How do I fix CVE-2015-4511?
To fix CVE-2015-4511, update Mozilla Firefox to version 41.0 or later, or Firefox ESR to version 38.3 or later.
3
What are the affected versions in CVE-2015-4511?
CVE-2015-4511 affects Mozilla Firefox versions before 41.0 and multiple versions of Firefox ESR before 38.3.
4
What type of vulnerability is CVE-2015-4511?
CVE-2015-4511 is classified as a heap-based buffer overflow vulnerability.
5
Can CVE-2015-4511 be exploited by attackers?
Yes, CVE-2015-4511 can be exploited by attackers through a crafted header in a WebM video.