CVE-2015-7216: Input Validation
The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JPEG 2000 image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7216?
CVE-2015-7216 has been classified as a moderate severity vulnerability due to the potential denial of service effects.
How do I fix CVE-2015-7216?
To fix CVE-2015-7216, update Mozilla Firefox to version 43.0 or later on affected Fedora or openSUSE systems.
Which versions of Firefox are affected by CVE-2015-7216?
CVE-2015-7216 affects all versions of Mozilla Firefox up to and including 42.0.
Are Fedora and openSUSE affected by CVE-2015-7216?
Yes, both Fedora 22, 23 and openSUSE versions 13.1, 13.2, and 42.1 are affected by CVE-2015-7216.
What kind of attacks can CVE-2015-7216 enable?
CVE-2015-7216 can allow remote attackers to exploit a crafted JPEG 2000 image to cause a denial of service.