CVE-2015-7203: Buffer Overflow
Published Dec 16, 2015
·Updated
Buffer overflow in the DirectWriteFontInfo::LoadFontFamilyData function in gfx/thebes/gfxDWriteFontList.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted font-family name.
Affected Software
6 affected components
Mozilla Firefox<=42.0
Fedoraproject Fedora=22
Fedoraproject Fedora=23
openSUSE Leap=42.1
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Event History
Dec 16, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7203?
CVE-2015-7203 has a moderate severity rating due to the potential for denial of service and remote attacks.
2
How do I fix CVE-2015-7203?
To fix CVE-2015-7203, upgrade to Mozilla Firefox version 43.0 or later.
3
Which versions of Firefox are affected by CVE-2015-7203?
CVE-2015-7203 affects Mozilla Firefox versions prior to 43.0.
4
Are specific Linux distributions affected by CVE-2015-7203?
Yes, CVE-2015-7203 affects Fedora versions 22 and 23, as well as openSUSE versions 13.1, 13.2, and Leap 42.1.
5
What type of attack is possible with CVE-2015-7203?
CVE-2015-7203 allows remote attackers to exploit a buffer overflow vulnerability leading to potential denial of service.