First published: Sat Aug 08 2015(Updated: )
Integer signedness error in the SharedBufferManagerParent::RecvAllocateGrallocBuffer function in the buffer-management implementation in the graphics layer in Mozilla Firefox OS before 2.2 might allow attackers to cause a denial of service (memory corruption) via a negative value of a size parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox OS | <=2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5962 is considered a medium severity vulnerability that may lead to denial of service through memory corruption.
CVE-2015-5962 affects Mozilla Firefox OS versions prior to 2.2, including 2.1.0 and earlier.
To resolve CVE-2015-5962, update your Mozilla Firefox OS to version 2.2 or later.
CVE-2015-5962 enables attackers to cause a denial of service attack through a memory corruption vulnerability.
Yes, CVE-2015-5962 can potentially be exploited remotely if an attacker manipulates the size parameter.