CVE-2015-7219

Publication date

2015-12-16 11:00:00

Family

mozilla

State

PUBLISHED

Description

The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a malformed PushPromise frame that triggers decompressed-buffer length miscalculation and incorrect memory allocation.