CVE-2015-0823: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 3.9% chance of exploitation in the next 30 days.

Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36.0, might allow remote attackers to trigger problematic Developer Console information or possibly have unspecified other impact by leveraging incorrect macro expansion, related to the ots::ots_gasp_parse function.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 14.10 only
  • Mozilla Firefox: up to and including 35.0.1; version 0.1 only; version 0.2 only; version 0.3 only; version 0.4 only; version 0.5 only; …
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Opentype Sanitiser Project Opentype Sanitiser: any version

Published 2015-02-25. Last modified 2026-06-17.