Rapid7 Vulnerability & Exploit Database

MFSA2015-97 Firefox: Memory leak in mozTCPSocket to servers (CVE-2015-4503)

Back to Search

MFSA2015-97 Firefox: Memory leak in mozTCPSocket to servers (CVE-2015-4503)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
09/22/2015
Created
07/25/2018
Added
09/23/2015
Modified
04/05/2017

Description

The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open method call and send method calls, which allows remote TCP servers to obtain sensitive information from process memory by reading packet data, as demonstrated by availability of this API in a Firefox OS application.

Solution(s)

  • mozilla-firefox-upgrade-41_0

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;