CVE-2015-7181: Buffer Overflow
Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-poison in the secasn1dparseleaf() function. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.
Other sources
The secasn1dparseleaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a "use-after-poison" issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7181?
CVE-2015-7181 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2015-7181?
To fix CVE-2015-7181, update affected systems to the latest patched versions of Mozilla Firefox or Mozilla NSS ESR available.
Which versions of Firefox are affected by CVE-2015-7181?
CVE-2015-7181 affects Mozilla Firefox versions up to and including 41.0.2.
Can CVE-2015-7181 be exploited through any means?
Yes, CVE-2015-7181 can be exploited by persuading a victim to visit a specially-crafted website.
Is there an official patch for CVE-2015-7181?
Yes, Mozilla has released official patches to address CVE-2015-7181 in affected software versions.