CVE-2015-0813
Publication date 1 April 2015
Last updated 24 July 2024
Ubuntu priority
Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
14.04 LTS trusty |
Fixed 37.0+build2-0ubuntu0.14.04.1
|
|
thunderbird | ||
14.04 LTS trusty |
Fixed 1:31.6.0+build1-0ubuntu0.14.04.1
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2552-1
- Thunderbird vulnerabilities
- 2 April 2015
- USN-2550-1
- Firefox vulnerabilities
- 1 April 2015