CVE-2016-2814
Summary
| CVE | CVE-2016-2814 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-04-30 17:59:00 UTC |
| Updated | 2017-07-01 01:29:00 UTC |
| Description | Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allows remote attackers to execute arbitrary code via crafted CENC offsets that lead to mismanagement of the sizes table. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
|
| Mozilla Firefox, Thunderbird: Multiple vulnerabilities (GLSA 201701-15) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [security-announce] openSUSE-SU-2016:1211-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| openSUSE-SU-2016:1251-1: moderate: Security update to Firefox 46.0 |
SUSE |
lists.opensuse.org |
|
| USN-2936-2: Oxygen-GTK3 update | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| Buffer overflow in libstagefright with CENC offsets — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Oracle Linux Bulletin - April 2016 |
CONFIRM |
www.oracle.com |
|
| USN-2936-1: Firefox vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| [security-announce] SUSE-SU-2016:1258-1: important: Security update for |
SUSE |
lists.opensuse.org |
|
| USN-2936-3: Firefox regression | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| [security-announce] SUSE-SU-2016:1374-1: important: Security update for |
SUSE |
lists.opensuse.org |
|
| Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Gain Elevated Privileges, Bypass Security Restrictions, and Obtain Potentially Sensitive Information - SecurityTracker |
SECTRACK |
www.securitytracker.com |
|
| Debian -- Security Information -- DSA-3559-1 iceweasel |
DEBIAN |
www.debian.org |
|
| 1254721 - (CVE-2016-2814) Crash [@ stagefright::SampleTable::parseSampleCencInfo] with heap buffer overflow in libstagefright. |
CONFIRM |
bugzilla.mozilla.org |
|
| [security-announce] SUSE-SU-2016:1352-1: important: Security update for |
SUSE |
lists.opensuse.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710500 Gentoo Linux Mozilla Firefox, Thunderbird Multiple Vulnerabilities (GLSA 201701-15)