Vulnerability Change Records for CVE-2015-4491

Change History

CVE Modified by Mozilla Corporation 12/23/2016 9:59:18 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
http://rhn.redhat.com/errata/RHSA-2015-1586.html [No Types Assigned]
Added Reference

								
							
							
						
http://rhn.redhat.com/errata/RHSA-2015-1682.html [No Types Assigned]
Added Reference

								
							
							
						
http://www.debian.org/security/2015/dsa-3337 [No Types Assigned]
Added Reference

								
							
							
						
http://www.securitytracker.com/id/1033247 [No Types Assigned]
Added Reference

								
							
							
						
http://www.ubuntu.com/usn/USN-2702-3 [No Types Assigned]
Added Reference

								
							
							
						
http://www.ubuntu.com/usn/USN-2712-1 [No Types Assigned]
Added Reference

								
							
							
						
http://www.ubuntu.com/usn/USN-2722-1 [No Types Assigned]

CVE Translated 8/27/2015 7:45:10 AM

Action Type Old Value New Value
Added Translation

								
							
							
						
Vulnerabilidad de desbordamiento de entero en la función make_filter_table en pixops/pixops.c en gdk-pixbuf en versiones anteriores a 2.31.5, tal como es usado en Mozilla Firefox en versiones anteriores a 40.0 y Firefox ESR 38.x en versiones anteriores a 38.2 en Linux, Google Chrome en Linux y otros productos, permite a atacantes remotos ejecutar código arbitrario o provocar una denegación de servicio (desbordamiento de buffer basado en memoria dinámica y caída de aplicación) a través de dimensiones bitmap manipuladas que no son manejadas correctamente durante el escalado..
Removed Translation
Vulnerabilidad de desbordamiento de entero en la función make_filter_table en pixops/pixops.c en gdk-pixbuf en versiones anteriores a 2.31.5, tal como es usado en Mozilla Firefox en versiones anteriores a 40.0 y Firefox ESR 38.x en versiones anteriores a 38.2 en Linux, Google Chrome en Linux y otros productos, permite a atacantes remotos ejecutar código arbitrario o provocar una denegación de servicio (mediante un desbordamiento de buffer basado en memoria dinámica y caída de aplicación) a través de dimensiones bitmap manipuladas que no son manejadas correctamente durante el escalado.

								
						

CVE Modified by Mozilla Corporation 12/21/2016 9:59:54 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165703.html [No Types Assigned]
Added Reference

								
							
							
						
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165732.html [No Types Assigned]
Added Reference

								
							
							
						
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.html [No Types Assigned]
Added Reference

								
							
							
						
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00016.html [No Types Assigned]
Added Reference

								
							
							
						
http://lists.opensuse.org/opensuse-updates/2015-08/msg00030.html [No Types Assigned]
Added Reference

								
							
							
						
http://lists.opensuse.org/opensuse-updates/2015-08/msg00031.html [No Types Assigned]
Added Reference

								
							
							
						
http://lists.opensuse.org/opensuse-updates/2015-09/msg00002.html [No Types Assigned]
Added Reference

								
							
							
						
http://rhn.redhat.com/errata/RHSA-2015-1694.html [No Types Assigned]
Added Reference

								
							
							
						
http://www.securitytracker.com/id/1033372 [No Types Assigned]

CVE Modified by Source 8/25/2015 10:2:27 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.html
Added Reference

								
							
							
						
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.html
Added Reference

								
							
							
						
http://www.ubuntu.com/usn/USN-2702-1
Added Reference

								
							
							
						
http://www.ubuntu.com/usn/USN-2702-2

Modified Analysis 8/18/2015 2:45:29 PM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
Configuration 1
     AND
          OR
               *cpe:2.3:a:gnome:gdk-pixbuf:2.31.4:*:*:*:*:*:*:* (and previous)
          OR
               cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.0.1:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.0.5:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.1.0:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox:39.0.3:*:*:*:*:*:*:* (and previous)
               cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
               cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:*
Added CVSS V2

								
							
							
						
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Added CWE

								
							
							
						
CWE-189
Changed Reference Type
http://www.mozilla.org/security/announce/2015/mfsa2015-88.html No Types Assigned
http://www.mozilla.org/security/announce/2015/mfsa2015-88.html Advisory

Initial CVE Analysis 10/18/2016 10:57:31 AM

Action Type Old Value New Value
Changed CPE Configuration
Configuration 1
     OR
          *cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
          *cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
          *cpe:2.3:o:novell:opensuse:13.1:*:*:*:*:*:*:*
          *cpe:2.3:o:novell:opensuse:13.2:*:*:*:*:*:*:*
          *cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
          *cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
          *cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
Configuration 2
     AND
          OR
               *cpe:2.3:a:gnome:gdk-pixbuf:2.31.4:*:*:*:*:*:*:* (and previous)
          OR
               cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.0.1:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.0.5:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.1.0:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox:39.0.3:*:*:*:*:*:*:* (and previous)
               cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
               cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:*
Configuration 1
     OR
          *cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*
          *cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
Configuration 2
     OR
          *cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
          *cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
          *cpe:2.3:o:novell:opensuse:13.1:*:*:*:*:*:*:*
          *cpe:2.3:o:novell:opensuse:13.2:*:*:*:*:*:*:*
          *cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
          *cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
          *cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
Configuration 3
     AND
          OR
               *cpe:2.3:a:gnome:gdk-pixbuf:2.31.4:*:*:*:*:*:*:* (and previous)
          OR
               cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.0.1:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.0.5:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.1.0:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox:39.0.3:*:*:*:*:*:*:* (and previous)
               cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
               cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:*
Changed Reference Type
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165701.html No Types Assigned
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165701.html Third Party Advisory
Changed Reference Type
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165730.html No Types Assigned
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165730.html Third Party Advisory
Changed Reference Type
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.html No Types Assigned
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.html Third Party Advisory
Changed Reference Type
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.html No Types Assigned
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.html Third Party Advisory
Changed Reference Type
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html No Types Assigned
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html Third Party Advisory
Changed Reference Type
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html No Types Assigned
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html Third Party Advisory
Changed Reference Type
http://www.ubuntu.com/usn/USN-2702-1 No Types Assigned
http://www.ubuntu.com/usn/USN-2702-1 Third Party Advisory
Changed Reference Type
http://www.ubuntu.com/usn/USN-2702-2 No Types Assigned
http://www.ubuntu.com/usn/USN-2702-2 Third Party Advisory

CVE Modified by Source 9/22/2015 9:59:03 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165701.html
Added Reference

								
							
							
						
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165730.html

CPE Deprecation Remap 10/30/2018 12:27:37 PM

Action Type Old Value New Value
Changed CPE Configuration
OR
     *cpe:2.3:o:novell:opensuse:13.2:*:*:*:*:*:*:*
OR
     *cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*

CVE Modified by Mozilla Corporation 12/07/2016 1:12:58 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html [No Types Assigned]
Added Reference

								
							
							
						
https://security.gentoo.org/glsa/201512-05 [No Types Assigned]

CVE Modified by Mozilla Corporation 11/30/2016 10:0:03 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://security.gentoo.org/glsa/201605-06 [No Types Assigned]

CPE Deprecation Remap 10/30/2018 12:27:35 PM

Action Type Old Value New Value
Changed CPE Configuration
OR
     *cpe:2.3:o:novell:opensuse:13.1:*:*:*:*:*:*:*
OR
     *cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*

CVE Modified by Source 10/03/2016 10:4:08 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html

Modified Analysis 8/26/2015 1:20:25 PM

Action Type Old Value New Value
Changed CPE Configuration
Configuration 1
     AND
          OR
               *cpe:2.3:a:gnome:gdk-pixbuf:2.31.4:*:*:*:*:*:*:* (and previous)
          OR
               cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.0.1:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.0.5:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.1.0:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox:39.0.3:*:*:*:*:*:*:* (and previous)
               cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
               cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:*
Configuration 1
     OR
          *cpe:2.3:o:novell:opensuse:13.1:*:*:*:*:*:*:*
          *cpe:2.3:o:novell:opensuse:13.2:*:*:*:*:*:*:*
          *cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
          *cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
          *cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
Configuration 2
     AND
          OR
               *cpe:2.3:a:gnome:gdk-pixbuf:2.31.4:*:*:*:*:*:*:* (and previous)
          OR
               cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.0.1:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.0.5:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.1.0:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox:39.0.3:*:*:*:*:*:*:* (and previous)
               cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
               cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:*

CVE Modified by Source 10/17/2016 11:47:09 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html

Initial CVE Analysis 8/18/2015 2:9:58 PM

Action Type Old Value New Value

Modified Analysis 10/18/2016 2:49:54 PM

Action Type Old Value New Value
Changed CPE Configuration
Configuration 1
     AND
          OR
               *cpe:2.3:a:gnome:gdk-pixbuf:2.31.4:*:*:*:*:*:*:* (and previous)
          OR
               cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.0.1:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.0.5:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.1.0:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox:39.0.3:*:*:*:*:*:*:* (and previous)
               cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
               cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:*
Configuration 2
     OR
          *cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
          *cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
          *cpe:2.3:o:novell:opensuse:13.1:*:*:*:*:*:*:*
          *cpe:2.3:o:novell:opensuse:13.2:*:*:*:*:*:*:*
          *cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
          *cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
          *cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
Configuration 1
     AND
          OR
               *cpe:2.3:a:gnome:gdk-pixbuf:2.31.4:*:*:*:*:*:*:* (and previous)
          OR
               cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.0.1:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.0.5:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox_esr:38.1.0:*:*:*:*:*:*:*
               cpe:2.3:a:mozilla:firefox:39.0.3:*:*:*:*:*:*:* (and previous)
               cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
               cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:*
Configuration 2
     OR
          *cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*
          *cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
Configuration 3
     OR
          *cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
          *cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
          *cpe:2.3:o:novell:opensuse:13.1:*:*:*:*:*:*:*
          *cpe:2.3:o:novell:opensuse:13.2:*:*:*:*:*:*:*
          *cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
          *cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
          *cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
Changed Reference Type
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165701.html No Types Assigned
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165701.html Third Party Advisory
Changed Reference Type
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165730.html No Types Assigned
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165730.html Third Party Advisory
Changed Reference Type
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.html No Types Assigned
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.html Third Party Advisory
Changed Reference Type
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.html No Types Assigned
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.html Third Party Advisory
Changed Reference Type
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html No Types Assigned
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html Third Party Advisory
Changed Reference Type
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html No Types Assigned
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html Third Party Advisory
Changed Reference Type
http://www.ubuntu.com/usn/USN-2702-1 No Types Assigned
http://www.ubuntu.com/usn/USN-2702-1 Third Party Advisory
Changed Reference Type
http://www.ubuntu.com/usn/USN-2702-2 No Types Assigned
http://www.ubuntu.com/usn/USN-2702-2 Third Party Advisory
Changed Reference Type
https://bugzilla.gnome.org/show_bug.cgi?id=752297 No Types Assigned
https://bugzilla.gnome.org/show_bug.cgi?id=752297 Issue Tracking
Changed Reference Type
https://bugzilla.mozilla.org/show_bug.cgi?id=1184009 No Types Assigned
https://bugzilla.mozilla.org/show_bug.cgi?id=1184009 Issue Tracking
Changed Reference Type
https://bugzilla.redhat.com/show_bug.cgi?id=1252290 No Types Assigned
https://bugzilla.redhat.com/show_bug.cgi?id=1252290 Issue Tracking