First published: Sun Mar 13 2016(Updated: )
Use-after-free vulnerability in the DesktopDisplayDevice class in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows | ||
Mozilla Firefox | <=44.0.2 | |
Webrtc Project Webrtc |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1976 has a severity rating that may allow remote attackers to exploit the vulnerability, leading to potential denial of service.
To fix CVE-2016-1976, users should upgrade to Mozilla Firefox version 45.0 or later, which addresses the use-after-free vulnerability.
CVE-2016-1976 affects Mozilla Firefox versions up to and including 44.0.2 on Windows.
While the primary risk of CVE-2016-1976 is denial of service, it could indirectly lead to data loss through application crashes.
Yes, the WebRTC implementation as found in Mozilla Firefox is associated with CVE-2016-1976.