CVE-2015-4503

Publication date 24 September 2015

Last updated 24 July 2024


Ubuntu priority

Description

The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open method call and send method calls, which allows remote TCP servers to obtain sensitive information from process memory by reading packet data, as demonstrated by availability of this API in a Firefox OS application.

Read the notes from the security team

Status

Package Ubuntu Release Status
firefox 15.04 vivid
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected

Notes


chrisccoulson

Firefox OS only


Access our resources on patching vulnerabilities