Bugzilla – Bug 928116
VUL-0: CVE-2015-2706 MozillaFirefox: Memory corruption during failed plugin initialization (MFSA 2015-45)
Last modified: 2020-04-05 18:19:07 UTC
Memory corruption during failed plugin initialization Announced: April 20, 2015 Reporter: Robert Kaiser Impact: High Products: Firefox Fixed in: Firefox 37.0.2 Description: Mozilla developer Robert Kaiser (Kairo) reported that a race condition when initialization of a plugin fails led to a potentially exploitable use-after-free vulnerability. References: https://www.mozilla.org/en-US/security/advisories/mfsa2015-45/ https://bugzilla.mozilla.org/show_bug.cgi?id=1141081 https://bugzilla.redhat.com/show_bug.cgi?id=1213935 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-2706 http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-2706.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2706 openSUSE only.
This is an autogenerated message for OBS integration: This bug (928116) was mentioned in https://build.opensuse.org/request/show/298646 Factory / MozillaFirefox https://build.opensuse.org/request/show/298648 13.2 / MozillaFirefox https://build.opensuse.org/request/show/298649 13.1 / MozillaFirefox
bugbot adjusting priority
Thanks for the submission, updates are running.
openSUSE-SU-2015:0763-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 928116 CVE References: CVE-2015-2706 Sources used: openSUSE 13.2 (src): MozillaFirefox-37.0.2-27.1
Released