Vulnerability Description
GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gstreamer | Gstreamer | < 1.4.5 |
| Mozilla | Firefox | < 38.0 |
| Mozilla | Seamonkey | < 2.35 |
| Mozilla | Thunderbird | < 31.7 |
| Linux | Linux Kernel | - |
| Suse | Linux Enterprise Desktop | 11 |
| Suse | Linux Enterprise Server | 11 |
| Suse | Linux Enterprise Software Development Kit | 11 |
| Redhat | Enterprise Linux Desktop | 5.0 |
| Redhat | Enterprise Linux Eus | 6.6 |
| Redhat | Enterprise Linux Server | 5.0 |
| Redhat | Enterprise Linux Server Aus | 6.6 |
| Redhat | Enterprise Linux Server Tus | 6.6 |
| Redhat | Enterprise Linux Workstation | 5.0 |
| Debian | Debian Linux | 7.0 |
References
- http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00017.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00054.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00000.htmlMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0988.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1012.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3225Third Party Advisory
- http://www.debian.org/security/2015/dsa-3260Third Party Advisory
- http://www.debian.org/security/2015/dsa-3264Third Party Advisory
- http://www.mozilla.org/security/announce/2015/mfsa2015-47.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlThird Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1080995Issue TrackingPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/03/msg00038.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/201512-07Third Party Advisory
- https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thundeVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00017.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2015-0797?
CVE-2015-0797 is a vulnerability with a CVSS score of 6.8 (MEDIUM). GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-re...
How severe is CVE-2015-0797?
CVE-2015-0797 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-0797?
Check the references section above for vendor advisories and patch information. Affected products include: Gstreamer Gstreamer, Mozilla Firefox, Mozilla Seamonkey, Mozilla Thunderbird, Linux Linux Kernel.