CVE-2015-4487
Publication date 11 August 2015
Last updated 24 July 2024
Ubuntu priority
Description
The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, related to an "overflow."
Status
| Package | Ubuntu Release | Status | 
|---|---|---|
| firefox | ||
| 14.04 LTS trusty | 
                              
                               
                                Fixed 40.0+build4-0ubuntu0.14.04.1 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| thunderbird | ||
| 14.04 LTS trusty | 
                              
                               
                                Fixed 1:38.2.0+build1-0ubuntu0.14.04.1 
                                
                               
                             |      
                          
                            
                          
                        
                      |
References
Related Ubuntu Security Notices (USN)
- USN-2702-1
 - Firefox vulnerabilities
 - 11 August 2015
 - USN-2712-1
 - Thunderbird vulnerabilities
 - 25 August 2015