Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-2738
HistoryJul 05, 2015 - 12:00 a.m.

CVE-2015-2738

2015-07-0500:00:00
ubuntu.com
ubuntu.com
19

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.007

Percentile

80.0%

The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr
implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8
and 38.x before 38.1, and Thunderbird before 38.1 reads data from
uninitialized memory locations, which has unspecified impact and attack
vectors.

OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchfirefox< 39.0+build5-0ubuntu0.12.04.2UNKNOWN
ubuntu14.04noarchfirefox< 39.0+build5-0ubuntu0.14.04.1UNKNOWN
ubuntu14.10noarchfirefox< 39.0+build5-0ubuntu0.14.10.1UNKNOWN
ubuntu15.04noarchfirefox< 39.0+build5-0ubuntu0.15.04.1UNKNOWN
ubuntu12.04noarchthunderbird< 1:31.8.0+build1-0ubuntu0.12.04.1UNKNOWN
ubuntu14.04noarchthunderbird< 1:31.8.0+build1-0ubuntu0.14.04.1UNKNOWN
ubuntu14.10noarchthunderbird< 1:31.8.0+build1-0ubuntu0.14.10.1UNKNOWN
ubuntu15.04noarchthunderbird< 1:31.8.0+build1-0ubuntu0.15.04.1UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.007

Percentile

80.0%