Input validation error in Debian Linux - CVE-2015-3417

 

Input validation error in Debian Linux - CVE-2015-3417

Published: April 24, 2015 / Updated: August 9, 2020


Vulnerability identifier: #VU40808
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2015-3417
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Debian
Affected software:
Debian Linux

Detailed vulnerability description

The vulnerability allows remote attackers to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data.


How to mitigate CVE-2015-3417

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Sources