First published: Sun Mar 13 2016(Updated: )
Race condition in libvpx in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <=44.0.2 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1972 is classified as a moderate severity vulnerability due to its potential for causing denial of service.
To fix CVE-2016-1972, update Mozilla Firefox to version 45.0 or later.
CVE-2016-1972 can be exploited through a race condition leading to a use-after-free condition.
CVE-2016-1972 affects Mozilla Firefox versions before 45.0 on Windows.
CVE-2016-1972 specifically impacts the libvpx component of Mozilla Firefox and does not affect other systems.