CERT-In Vulnerability Note
CIVN-2016-0309
Use after free Vulnerability in Mozilla Products
Original Issue Date:December 14, 2016
Severity Rating: HIGH
Systems Affected
- Firefox prior to 50.0.2
- Firefox ESR prior to 45.5.1
- Thunderbird prior to 45.5.1
Overview
A use-after-free vulnerability has been reported in Mozilla products which could be exploited by a remote attacker to execute arbitrary code on the affected system.
Description
This vulnerability exists in Mozilla products due to use-after-free memory error in SVG animation functionality. A remote attacker could exploit this vulnerability by convincing a user to open a specially crafted JavaScript which could trigger use-after-free memory error in SVG animation. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on the affected system.
Note: This vulnerability is being actively exploited against Firefox and the Tor Browser on Windows-based systems.
Solution
Apply appropriate updates as mentioned in
MFSA2016-92
Vendor Information
Mozilla
https://www.mozilla.org/en-US/security/advisories/mfsa2016-92/
References
Mozilla
https://www.mozilla.org/en-US/security/advisories/mfsa2016-92/
Security tracker
http://securitytracker.com/id/1037370
CVE Name
CVE-2016-9079
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|