CVE-2016-1956: High severity firefox vulnerability
Published Mar 13, 2016
·Updated
Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.
Affected Software
6 affected components
Mozilla Firefox<=44.0.2
Linux Linux kernel
Novell Suse Package Hub For Suse Linux Enterprise=12
openSUSE Leap=42.1
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Event History
Mar 13, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1956?
CVE-2016-1956 has a medium severity level as it can lead to denial of service conditions.
2
How do I fix CVE-2016-1956?
To remediate CVE-2016-1956, users should update their Mozilla Firefox to version 45.0 or later.
3
Who is affected by CVE-2016-1956?
CVE-2016-1956 affects users of Mozilla Firefox versions prior to 45.0 on Linux systems using certain Intel video drivers.
4
What type of vulnerability is CVE-2016-1956?
CVE-2016-1956 is classified as a denial of service vulnerability due to memory consumption or stack memory corruption.
5
Can CVE-2016-1956 be exploited remotely?
Yes, CVE-2016-1956 can be exploited remotely by attackers through specially crafted WebGL shaders.