First published: Wed Dec 16 2015(Updated: )
Mozilla Firefox before 43.0 does not properly store the properties of unboxed objects, which allows remote attackers to execute arbitrary code via crafted JavaScript variable assignments.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE | =42.1 | |
openSUSE | =13.1 | |
openSUSE | =13.2 | |
Fedoraproject Fedora | =22 | |
Fedoraproject Fedora | =23 | |
Mozilla Firefox | <=42.0 | |
Mozilla Firefox | =41.0 | |
Mozilla Firefox | =41.0.1 | |
Mozilla Firefox | =41.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7204 has a medium severity rating due to its potential for remote code execution.
To fix CVE-2015-7204, upgrade to Mozilla Firefox version 43.0 or later, or apply the relevant patches provided by your operating system vendor.
CVE-2015-7204 affects all versions of Mozilla Firefox prior to 43.0.
Yes, CVE-2015-7204 can be exploited by remote attackers through crafted JavaScript variable assignments.
CVE-2015-7204 impacts multiple Linux distributions including openSUSE versions 13.1, 13.2, and 42.1, as well as Fedora versions 22 and 23.