CVE-2016-2837
Summary
| CVE | CVE-2016-2837 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-08-05 01:59:00 UTC |
| Updated | 2019-12-27 16:08:00 UTC |
| Description | Heap-based buffer overflow in the ClearKey Content Decryption Module (CDM) in the Encrypted Media Extensions (EME) API in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 might allow remote attackers to execute arbitrary code by providing a malformed video and leveraging a Gecko Media Plugin (GMP) sandbox bypass. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Buffer overflow in ClearKey Content Decryption Module (CDM) during video playback — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Mozilla Firefox Multiple Security Vulnerabilities |
BID |
www.securityfocus.com |
|
| [security-announce] openSUSE-SU-2016:1964-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| [security-announce] openSUSE-SU-2016:2026-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| Mozilla Firefox, Thunderbird: Multiple vulnerabilities (GLSA 201701-15) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Oracle Linux Bulletin - July 2016 |
CONFIRM |
www.oracle.com |
Third Party Advisory |
| USN-3044-1: Firefox vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| Zero Day Initiative |
MISC |
www.zerodayinitiative.com |
|
| Debian -- Security Information -- DSA-3640-1 firefox-esr |
DEBIAN |
www.debian.org |
|
| Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Bypass Security Restrictions, Spoof Content, Modify Files, and Obtain Potentially Sensitive Information - SecurityTracker |
SECTRACK |
www.securitytracker.com |
|
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
|
| 1274637 - (CVE-2016-2837) ZDI-CAN-3766: Mozilla Firefox ClearKeyDecryptor Heap Buffer Overflow Remote Code Execution Vulnerability |
CONFIRM |
bugzilla.mozilla.org |
Issue Tracking, Permissions Required |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710500 Gentoo Linux Mozilla Firefox, Thunderbird Multiple Vulnerabilities (GLSA 201701-15)