CVE-2015-7200

The CryptoKey interface implementation in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 lacks status checking, which allows attackers to have an unspecified impact via vectors related to a cryptographic key.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00013.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00020.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00021.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html
http://lists.opensuse.org/opensuse-updates/2015-12/msg00037.html
http://lists.opensuse.org/opensuse-updates/2015-12/msg00049.html
http://rhn.redhat.com/errata/RHSA-2015-1982.html
http://rhn.redhat.com/errata/RHSA-2015-2519.html
http://www.debian.org/security/2015/dsa-3393
http://www.debian.org/security/2015/dsa-3410
http://www.mozilla.org/security/announce/2015/mfsa2015-131.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
http://www.securityfocus.com/bid/77411
http://www.securitytracker.com/id/1034069
http://www.ubuntu.com/usn/USN-2785-1
http://www.ubuntu.com/usn/USN-2819-1
https://bugzilla.mozilla.org/show_bug.cgi?id=1204155
https://security.gentoo.org/glsa/201512-10
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00013.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00020.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00021.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html
http://lists.opensuse.org/opensuse-updates/2015-12/msg00037.html
http://lists.opensuse.org/opensuse-updates/2015-12/msg00049.html
http://rhn.redhat.com/errata/RHSA-2015-1982.html
http://rhn.redhat.com/errata/RHSA-2015-2519.html
http://www.debian.org/security/2015/dsa-3393
http://www.debian.org/security/2015/dsa-3410
http://www.mozilla.org/security/announce/2015/mfsa2015-131.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
http://www.securityfocus.com/bid/77411
http://www.securitytracker.com/id/1034069
http://www.ubuntu.com/usn/USN-2785-1
http://www.ubuntu.com/usn/USN-2819-1
https://bugzilla.mozilla.org/show_bug.cgi?id=1204155
https://security.gentoo.org/glsa/201512-10
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.2.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.2.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.3.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:36

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00013.html - () http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00013.html -
References () http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.html - () http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.html -
References () http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00020.html - () http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00020.html -
References () http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00021.html - () http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00021.html -
References () http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html - () http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html -
References () http://lists.opensuse.org/opensuse-updates/2015-12/msg00037.html - () http://lists.opensuse.org/opensuse-updates/2015-12/msg00037.html -
References () http://lists.opensuse.org/opensuse-updates/2015-12/msg00049.html - () http://lists.opensuse.org/opensuse-updates/2015-12/msg00049.html -
References () http://rhn.redhat.com/errata/RHSA-2015-1982.html - () http://rhn.redhat.com/errata/RHSA-2015-1982.html -
References () http://rhn.redhat.com/errata/RHSA-2015-2519.html - () http://rhn.redhat.com/errata/RHSA-2015-2519.html -
References () http://www.debian.org/security/2015/dsa-3393 - () http://www.debian.org/security/2015/dsa-3393 -
References () http://www.debian.org/security/2015/dsa-3410 - () http://www.debian.org/security/2015/dsa-3410 -
References () http://www.mozilla.org/security/announce/2015/mfsa2015-131.html - Vendor Advisory () http://www.mozilla.org/security/announce/2015/mfsa2015-131.html - Vendor Advisory
References () http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html - () http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html -
References () http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html - () http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html -
References () http://www.securityfocus.com/bid/77411 - () http://www.securityfocus.com/bid/77411 -
References () http://www.securitytracker.com/id/1034069 - () http://www.securitytracker.com/id/1034069 -
References () http://www.ubuntu.com/usn/USN-2785-1 - () http://www.ubuntu.com/usn/USN-2785-1 -
References () http://www.ubuntu.com/usn/USN-2819-1 - () http://www.ubuntu.com/usn/USN-2819-1 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1204155 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1204155 -
References () https://security.gentoo.org/glsa/201512-10 - () https://security.gentoo.org/glsa/201512-10 -

22 Oct 2024, 13:42

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox_esr:38.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.2.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.3.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.2.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.2.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.3.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.2.0:*:*:*:*:*:*:*

Information

Published : 2015-11-05 05:59

Updated : 2024-11-21 02:36


NVD link : CVE-2015-7200

Mitre link : CVE-2015-7200

CVE.ORG link : CVE-2015-7200


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-17

DEPRECATED: Code