Bugzilla – Bug 977381
VUL-0: CVE-2016-2814: MozillaFirefox: Buffer overflow in libstagefright with CENC offsets (MFSA 2016-44)
Last modified: 2020-04-05 18:21:29 UTC
https://www.mozilla.org/en-US/security/advisories/mfsa2016-44/ Using Address Sanitizer, security researcher Sascha Just reported a buffer overflow in the libstagefright library due to issues with the handling of CENC offsets and the sizes table. This results in a potentially exploitable crash triggerable through web content. Crash [@ stagefright::SampleTable::parseSampleCencInfo] with heap buffer overflow in libstagefright (CVE-2016-2814) https://bugzilla.mozilla.org/show_bug.cgi?id=1254721
An update workflow for this issue was started. This issue was rated as critical. Please submit fixed packages until 2016-04-29. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/62674
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (977381) was mentioned in https://build.opensuse.org/request/show/392977 Factory / MozillaFirefox https://build.opensuse.org/request/show/392978 42.1 / MozillaFirefox https://build.opensuse.org/request/show/392979 13.2 / MozillaFirefox https://build.opensuse.org/request/show/392980 13.1 / MozillaFirefox
All submission received, incidents running
openSUSE-SU-2016:1211-1: An update that fixes 10 vulnerabilities is now available. Category: security (important) Bug References: 977333,977373,977375,977376,977379,977381,977382,977384,977386,977388 CVE References: CVE-2016-2804,CVE-2016-2806,CVE-2016-2807,CVE-2016-2808,CVE-2016-2811,CVE-2016-2812,CVE-2016-2814,CVE-2016-2816,CVE-2016-2817,CVE-2016-2820 Sources used: openSUSE Leap 42.1 (src): MozillaFirefox-46.0-21.1, mozilla-nss-3.22.3-15.2 openSUSE 13.2 (src): MozillaFirefox-46.0-68.1, mozilla-nss-3.22.3-31.1
openSUSE-SU-2016:1251-1: An update that fixes 13 vulnerabilities is now available. Category: security (moderate) Bug References: 977333,977373,977375,977376,977377,977378,977379,977380,977381,977382,977384,977386,977388 CVE References: CVE-2016-2804,CVE-2016-2806,CVE-2016-2807,CVE-2016-2808,CVE-2016-2809,CVE-2016-2810,CVE-2016-2811,CVE-2016-2812,CVE-2016-2813,CVE-2016-2814,CVE-2016-2816,CVE-2016-2817,CVE-2016-2820 Sources used: openSUSE 13.1 (src): MozillaFirefox-46.0-113.2, mozilla-nss-3.22.3-77.1
SUSE-SU-2016:1258-1: An update that solves four vulnerabilities and has one errata is now available. Category: security (important) Bug References: 977333,977374,977376,977381,977386 CVE References: CVE-2016-2805,CVE-2016-2807,CVE-2016-2808,CVE-2016-2814 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP1 (src): MozillaFirefox-38.8.0esr-66.2 SUSE Linux Enterprise Software Development Kit 12 (src): MozillaFirefox-38.8.0esr-66.2 SUSE Linux Enterprise Server 12-SP1 (src): MozillaFirefox-38.8.0esr-66.2 SUSE Linux Enterprise Server 12 (src): MozillaFirefox-38.8.0esr-66.2 SUSE Linux Enterprise Desktop 12-SP1 (src): MozillaFirefox-38.8.0esr-66.2 SUSE Linux Enterprise Desktop 12 (src): MozillaFirefox-38.8.0esr-66.2
An update workflow for this issue was started. This issue was rated as important. Please submit fixed packages until 2016-05-18. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/62716
SUSE-SU-2016:1342-1: An update that solves four vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 977333,977374,977376,977381,977386 CVE References: CVE-2016-2805,CVE-2016-2807,CVE-2016-2808,CVE-2016-2814 Sources used: SUSE Linux Enterprise Server 11-SP2-LTSS (src): MozillaFirefox-38.8.0esr-40.1 SUSE Linux Enterprise Debuginfo 11-SP2 (src): MozillaFirefox-38.8.0esr-40.1
SUSE-SU-2016:1352-1: An update that solves four vulnerabilities and has one errata is now available. Category: security (important) Bug References: 977333,977374,977376,977381,977386 CVE References: CVE-2016-2805,CVE-2016-2807,CVE-2016-2808,CVE-2016-2814 Sources used: SUSE Linux Enterprise Server 10 SP4 LTSS (src): MozillaFirefox-38.8.0esr-0.5.1
SUSE-SU-2016:1374-1: An update that solves four vulnerabilities and has one errata is now available. Category: security (important) Bug References: 977333,977374,977376,977381,977386 CVE References: CVE-2016-2805,CVE-2016-2807,CVE-2016-2808,CVE-2016-2814 Sources used: SUSE OpenStack Cloud 5 (src): MozillaFirefox-38.8.0esr-40.5, mozilla-nspr-4.12-26.1, mozilla-nss-3.20.2-30.1 SUSE Manager Proxy 2.1 (src): MozillaFirefox-38.8.0esr-40.5, mozilla-nspr-4.12-26.1, mozilla-nss-3.20.2-30.1 SUSE Manager 2.1 (src): MozillaFirefox-38.8.0esr-40.5, mozilla-nspr-4.12-26.1, mozilla-nss-3.20.2-30.1 SUSE Linux Enterprise Software Development Kit 11-SP4 (src): MozillaFirefox-38.8.0esr-40.5, mozilla-nspr-4.12-26.1, mozilla-nss-3.20.2-30.1 SUSE Linux Enterprise Server 11-SP4 (src): MozillaFirefox-38.8.0esr-40.5, mozilla-nspr-4.12-26.1, mozilla-nss-3.20.2-30.1 SUSE Linux Enterprise Server 11-SP3-LTSS (src): MozillaFirefox-38.8.0esr-40.5, mozilla-nspr-4.12-26.1, mozilla-nss-3.20.2-30.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): MozillaFirefox-38.8.0esr-40.5, mozilla-nspr-4.12-26.1, mozilla-nss-3.20.2-30.1 SUSE Linux Enterprise Debuginfo 11-SP3 (src): MozillaFirefox-38.8.0esr-40.5, mozilla-nspr-4.12-26.1, mozilla-nss-3.20.2-30.1
released