Mozilla Foundation Security Advisory 2015-93

Integer overflows in libstagefright while processing MP4 video metadata

Announced
August 12, 2015
Reporter
Joshua Drake
Impact
Critical
Products
Firefox, SeaMonkey
Fixed in
  • Firefox 38
  • SeaMonkey 2.35

Description

Security researcher Joshua Drake reported potential integer overflows in the libstagefright library while processing video sample metadata in MPEG4 video files. This can lead to a potentially exploitable crash.

References