CVE-2016-2828: Use After Free
Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the texture's recycle pool.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2828?
CVE-2016-2828 is classified as a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2016-2828?
To fix CVE-2016-2828, update Mozilla Firefox to version 47.0 or later, or update Firefox ESR to version 45.2 or later.
What are the affected versions of Firefox for CVE-2016-2828?
Affected versions of Firefox for CVE-2016-2828 include all versions prior to 47.0, as well as Firefox ESR versions before 45.2.
What systems are impacted by CVE-2016-2828?
CVE-2016-2828 affects various Linux distributions such as Ubuntu 12.04, 14.04, 15.10, and 16.04, as well as openSUSE versions 13.1, 13.2, and 42.1.
How does CVE-2016-2828 exploit work?
CVE-2016-2828 exploits a use-after-free vulnerability that can occur in WebGL content, allowing attackers to access destroyed texture pools.