CVE-2015-0797: Debian Linux
Medium severity, CVSS 6.8. EPSS: 5.4% chance of exploitation in the next 30 days.
GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file.
Affected products
- Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
- Gstreamer Gstreamer: before 1.4.5 (fixed in 1.4.5)
- Mozilla Firefox: before 38.0 (fixed in 38.0); from 31.0, before 31.7 (fixed in 31.7)
- Mozilla Seamonkey: before 2.35 (fixed in 2.35)
- Mozilla Thunderbird: before 31.7 (fixed in 31.7); from 38.0, before 38.0.1 (fixed in 38.0.1)
- Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Eus: version 6.6 only; version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; …
- Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 6.6 only; version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server Tus: version 6.6 only; version 7.3 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only; version 7.0 only
- Suse Linux Enterprise Desktop: version 11 only
- Suse Linux Enterprise Server: version 11 only
- Suse Linux Enterprise Software Development Kit: version 11 only
Published 2015-05-14. Last modified 2026-06-17.