CVE-2016-9079

Scores

EPSS

0.848high84.8%
0%20%40%60%80%100%

Percentile: 84.8%

CVSS

7.3high3.x
0246810

CVSS Score: 7.3/10

All CVSS Scores

CVSS 3.x
7.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CVSS 2.0
6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Description

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdredhatubuntu

CWEs

CWE-416

Related Vulnerabilities

Exploits

Exploit ID: 41151

Source: exploitdb

URL: https://www.exploit-db.com/exploits/41151

Exploit ID: 42327

Source: exploitdb

URL: https://www.exploit-db.com/exploits/42327

Exploit ID: CVE-2016-9079

Source: github-poc

URL: https://github.com/Tau-hub/Firefox-CVE-2016-9079

Recommendations

Source: nvd

All Mozilla SeaMonkey users should upgrade to the latest version:
# emerge –sync
# emerge –ask –oneshot –verbose “>=www-client/seamonkey-2.46-r1”

All Mozilla SeaMonkey-bin users should upgrade to the latest version:
# emerge –sync
# emerge –ask –oneshot –verbose “>=www-client/seamonkey-bin-2.46”

URL: https://security.gentoo.org/glsa/201701-35

Source: nvd

For details on how to apply this update, which includes the changes described inthis advisory, refer to:
https://access.redhat.com/articles/11258
All running instances of Thunderbird must be restarted for the update to takeeffect.

URL: http://rhn.redhat.com/errata/RHSA-2016-2850.html

Source: nvd

For details on how to apply this update, which includes the changes described inthis advisory, refer to:
https://access.redhat.com/articles/11258
After installing the update, Firefox must be restarted for the changes to takeeffect.

URL: http://rhn.redhat.com/errata/RHSA-2016-2843.html

Vulnerable Software (31)

Type: Configuration

Product: firefox

Operating System: rhel 5

Trait:
{  "fixed": "45.5.1-1.el5_11"}

Source: redhat

Type: Configuration

Product: firefox

Operating System: rhel 6

Trait:
{  "fixed": "45.5.1-1.el6_8"}

Source: redhat

Type: Configuration

Product: firefox

Operating System: rhel 7

Trait:
{  "fixed": "45.5.1-1.el7_3"}

Source: redhat

Type: Configuration

Product: firefox

Operating System: ubuntu trusty 14.04

Trait:
{  "fixed": "50.0.2+build1-0ubuntu0.14.04.1"}

Source: ubuntu

Type: Configuration

Product: firefox

Operating System: ubuntu xenial 16.04

Trait:
{  "fixed": "50.0.2+build1-0ubuntu0.16.04.1"}

Source: ubuntu

Type: Configuration

Product: firefox

Operating System: ubuntu yakkety 16.10

Trait:
{  "fixed": "50.0.2+build1-0ubuntu0.16.10.1"}

Source: ubuntu

Type: Configuration

Product: firefox

Operating System: debian

Trait:
{  "fixed": "50.0.2-1"}

Source: debian

Type: Configuration

Product: firefox-esr

Operating System: debian

Trait:
{  "fixed": "45.5.1esr-1"}

Source: debian

Type: Configuration

Product: icedove

Operating System: debian

Trait:
{  "fixed": "1:45.5.1-1"}

Source: debian

Type: Configuration

Product: rpm-build-thunderbird

Operating System: altlinux

Trait:
{  "fixed": "0:45.5.1-alt1"}

Source: redhat

Type: Configuration

Product: thunderbird

Operating System: rhel 5

Trait:
{  "fixed": "45.5.1-1.el5_11"}

Source: redhat

Type: Configuration

Product: thunderbird

Operating System: rhel 6

Trait:
{  "fixed": "45.5.1-1.el6_8"}

Source: redhat

Type: Configuration

Product: thunderbird

Operating System: rhel 7

Trait:
{  "fixed": "45.5.1-1.el7_3"}

Source: redhat

Type: Configuration

Product: thunderbird

Operating System: ubuntu trusty 14.04

Trait:
{  "fixed": "1:45.5.1+build1-0ubuntu0.14.04.1"}

Source: ubuntu

Type: Configuration

Product: thunderbird

Operating System: ubuntu xenial 16.04

Trait:
{  "fixed": "1:45.5.1+build1-0ubuntu0.16.04.1"}

Source: ubuntu

Type: Configuration

Product: thunderbird

Operating System: ubuntu yakkety 16.10

Trait:
{  "fixed": "1:45.5.1+build1-0ubuntu0.16.10.1"}

Source: ubuntu

Type: Configuration

Product: thunderbird

Operating System: altlinux

Trait:
{  "fixed": "0:45.5.1-alt1"}

Source: redhat

Type: Configuration

Product: thunderbird-devel

Operating System: altlinux

Trait:
{  "fixed": "0:45.5.1-alt1"}

Source: redhat

Type: Configuration

Product: thunderbird-enigmail

Operating System: altlinux

Trait:
{  "fixed": "0:45.5.1-alt1"}

Source: redhat

Type: Configuration

Product: thunderbird-google-calendar

Operating System: altlinux

Trait:
{  "fixed": "0:45.5.1-alt1"}

Source: redhat