---
title: "CVE-2015-4475\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2015-4475?format=md
keywords: index, follow
---

# CVE-2015-4475

Publication date 11 August 2015

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox
ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3
audio data, which allows remote attackers to execute arbitrary code or
cause a denial of service (out-of-bounds read) via a malformed file.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 15.04 vivid | Fixed 40.0+build4-0ubuntu0.15.04.1 |
| 14.04 LTS trusty | Fixed 40.0+build4-0ubuntu0.14.04.1 |
| 12.04 LTS precise | Fixed 40.0+build4-0ubuntu0.12.04.1 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4475)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2015-4475)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2015-4475)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2015-4475)

### Related Ubuntu Security Notices (USN)

+ [USN-2702-1](https://usn.ubuntu.com/USN-2702-1)
+ Firefox vulnerabilities
+ 11 August 2015

### Other references

* <https://www.mozilla.org/en-US/security/advisories/mfsa2015-80/>
* <https://www.cve.org/CVERecord?id=CVE-2015-4475>
