CVE-2015-2710
Publication date 13 May 2015
Last updated 24 July 2024
Ubuntu priority
Heap-based buffer overflow in the SVGTextFrame class in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code via crafted SVG graphics data in conjunction with a crafted Cascading Style Sheets (CSS) token sequence.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
14.04 LTS trusty |
Fixed 38.0+build3-0ubuntu0.14.04.1
|
|
thunderbird | ||
14.04 LTS trusty |
Fixed 1:31.7.0+build1-0ubuntu0.14.04.1
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2603-1
- Thunderbird vulnerabilities
- 18 May 2015
- USN-2602-1
- Firefox vulnerabilities
- 13 May 2015