CVE-2016-2839

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 on Linux make cairo _cairo_surface_get_extents calls that do not properly interact with libav header allocation in FFmpeg 0.10, which allows remote attackers to cause a denial of service (application crash) via a crafted video.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:0.10:*:*:*:*:*:*:*
OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:45.1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:45.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:45.2.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:45.3.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2016-08-05 01:59

Updated : 2023-12-10 11:46


NVD link : CVE-2016-2839

Mitre link : CVE-2016-2839

CVE.ORG link : CVE-2016-2839


JSON object : View

Products Affected

mozilla

  • firefox_esr
  • firefox

linux

  • linux_kernel

ffmpeg

  • ffmpeg
CWE
CWE-20

Improper Input Validation