CVE-2016-2836: Buffer Overflow
Last updated 24 July 2024
Other sources
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to Http2Session::Shutdown and SpdySession31::Shutdown, and other vectors.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 138.0.1-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 128.9.0esr-1~deb11u1Fixed in 128.8.0esr-1~deb12u1Fixed in 128.10.0esr-1~deb12u1Fixed in 128.9.0esr-2Fixed in 128.10.0esr-1 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 48.0 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 45.3
Event History
Frequently Asked Questions
What is CVE-2016-2836?
CVE-2016-2836 is a vulnerability in Mozilla Firefox and Firefox ESR that allows remote attackers to cause a denial of service or execute arbitrary code.
How severe is CVE-2016-2836?
CVE-2016-2836 has a severity rating of 8.8, which is considered high.
What software versions are affected by CVE-2016-2836?
Mozilla Firefox versions up to 47.0.1 and Firefox ESR versions up to 45.3.0 are affected by CVE-2016-2836.
How can I fix CVE-2016-2836?
To fix CVE-2016-2836, update Mozilla Firefox to version 48.0 or later, or update Firefox ESR to version 45.3.1 or later.
Where can I find more information about CVE-2016-2836?
You can find more information about CVE-2016-2836 on the MITRE CVE website, Mozilla's security advisories page, and Bugzilla.