First published: Sun Mar 13 2016(Updated: )
Race condition in the GetStaticInstance function in the WebRTC implementation in Mozilla Firefox before 45.0 might allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via unspecified vectors.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Linux | =5.0 | |
Oracle Linux | =6 | |
Oracle Linux | =7 | |
Mozilla Firefox | <=44.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1973 has a high severity rating due to its potential to allow remote attackers to execute arbitrary code.
To fix CVE-2016-1973, users should update Mozilla Firefox to version 45.0 or later.
CVE-2016-1973 affects Mozilla Firefox versions prior to 45.0.
CVE-2016-1973 may allow remote attackers to execute arbitrary code or cause a denial of service due to a use-after-free vulnerability.
CVE-2016-1973 is caused by a race condition in the GetStaticInstance function in the WebRTC implementation in Firefox.