Your submission was sent successfully! Close

CVE-2015-4480

Published: 11 August 2015

Integer overflow in the stagefright::SampleTable::isValid function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via crafted MPEG-4 video data with H.264 encoding.

Priority

Medium

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
precise
Released (40.0+build4-0ubuntu0.12.04.1)
trusty Does not exist
(trusty was released [40.0+build4-0ubuntu0.14.04.1])
upstream
Released (40.0)
vivid
Released (40.0+build4-0ubuntu0.15.04.1)