CVE-2015-0797

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/05/2015
Last modified:
12/04/2025

Description

GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gstreamer_project:gstreamer:*:*:*:*:*:*:*:* 1.4.5 (excluding)
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 38.0 (excluding)
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 31.0 (including) 31.7 (excluding)
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* 2.35 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 31.7 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 38.0 (including) 38.0.1 (excluding)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp3:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:6.6:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools