First published: Sun Mar 13 2016(Updated: )
The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via crafted Unicode data in an HTML, XML, or SVG document.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <=44.0.2 | |
Mozilla Firefox | =38.0 | |
Mozilla Firefox | =38.0.1 | |
Mozilla Firefox | =38.0.5 | |
Mozilla Firefox | =38.1.0 | |
Mozilla Firefox | =38.1.1 | |
Mozilla Firefox | =38.2.0 | |
Mozilla Firefox | =38.2.1 | |
Mozilla Firefox | =38.3.0 | |
Mozilla Firefox | =38.4.0 | |
Mozilla Firefox | =38.5.0 | |
Mozilla Firefox | =38.5.1 | |
Mozilla Firefox | =38.6.0 | |
Mozilla Firefox | =38.6.1 | |
Mozilla Thunderbird | <=38.6.0 | |
Oracle Linux | =5.0 | |
Oracle Linux | =6 | |
Oracle Linux | =7 | |
openSUSE | =42.1 | |
openSUSE | =13.1 | |
openSUSE | =13.2 | |
SUSE Linux Enterprise Server | =12.0 | |
Mozilla Firefox ESR | =38.0 | |
Mozilla Firefox ESR | =38.0.1 | |
Mozilla Firefox ESR | =38.0.5 | |
Mozilla Firefox ESR | =38.1.0 | |
Mozilla Firefox ESR | =38.1.1 | |
Mozilla Firefox ESR | =38.2.0 | |
Mozilla Firefox ESR | =38.2.1 | |
Mozilla Firefox ESR | =38.3.0 | |
Mozilla Firefox ESR | =38.4.0 | |
Mozilla Firefox ESR | =38.5.0 | |
Mozilla Firefox ESR | =38.5.1 | |
Mozilla Firefox ESR | =38.6.0 | |
Mozilla Firefox ESR | =38.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1974 is classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2016-1974, update Mozilla Firefox to version 45.0 or later, or to Firefox ESR version 38.7 or later.
Mozilla Firefox versions before 45.0 and Firefox ESR versions before 38.7 are affected by CVE-2016-1974.
CVE-2016-1974 can be exploited through crafted Unicode data within HTML, potentially leading to arbitrary code execution or causing denial of service.
Yes, versions of Mozilla Thunderbird up to 38.6.0 are also affected by CVE-2016-1974.