---
title: "CVE-2015-0813\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2015-0813?format=md
keywords: index, follow
---

# CVE-2015-0813

Publication date 1 April 2015

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Use-after-free vulnerability in the AppendElements function in Mozilla
Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before
31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows
remote attackers to execute arbitrary code or cause a denial of service
(heap memory corruption) via a crafted MP3 file.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 14.10 utopic | Fixed 37.0+build2-0ubuntu0.14.10.1 |
| 14.04 LTS trusty | Fixed 37.0+build2-0ubuntu0.14.04.1 |
| 12.04 LTS precise | Fixed 37.0+build2-0ubuntu0.12.04.1 |
| 10.04 LTS lucid | Ignored end of life |
| thunderbird | 14.10 utopic | Fixed 1:31.6.0+build1-0ubuntu0.14.10.1 |
| 14.04 LTS trusty | Fixed 1:31.6.0+build1-0ubuntu0.14.04.1 |
| 12.04 LTS precise | Fixed 1:31.6.0+build1-0ubuntu0.12.04.1 |
| 10.04 LTS lucid | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0813)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2015-0813)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2015-0813)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2015-0813)

### Related Ubuntu Security Notices (USN)

+ [USN-2552-1](https://usn.ubuntu.com/USN-2552-1)
+ Thunderbird vulnerabilities
+ 2 April 2015

+ [USN-2550-1](https://usn.ubuntu.com/USN-2550-1)
+ Firefox vulnerabilities
+ 1 April 2015

### Other references

* <https://www.mozilla.org/en-US/security/advisories/mfsa2015-31/>
* <https://www.cve.org/CVERecord?id=CVE-2015-0813>
