Buffer over-read vulnerability in GStreamer before 1.4.5 allows remote attackers to cause denial of service or execute arbitrary code via crafted H.264 video data in an m4v file

Buffer over-read vulnerability in GStreamer before 1.4.5 allows remote attackers to cause denial of service or execute arbitrary code via crafted H.264 video data in an m4v file

CVE-2015-0797 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.