CVE-2016-2838: Buffer Overflow
Heap-based buffer overflow in the nsBidi::BracketData::AddOpening function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via directional content in an SVG document.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 137.0.2-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 128.9.0esr-1~deb11u1Fixed in 128.8.0esr-1~deb12u1Fixed in 128.9.0esr-1~deb12u1Fixed in 128.9.0esr-2 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 48.0 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 45.3
Event History
Frequently Asked Questions
What is CVE-2016-2838?
CVE-2016-2838 is a vulnerability in Mozilla Firefox that allows remote attackers to execute arbitrary code via directional content in an SVG document.
How severe is CVE-2016-2838?
CVE-2016-2838 has a severity score of 8.8, which is considered high.
Which software versions are affected by CVE-2016-2838?
Mozilla Firefox versions before 48.0 and Firefox ESR versions before 45.3 are affected by CVE-2016-2838.
How can I fix CVE-2016-2838?
To fix CVE-2016-2838, update Mozilla Firefox to version 48.0 or later, or update Firefox ESR to version 45.3 or later.
Where can I find more information about CVE-2016-2838?
More information about CVE-2016-2838 can be found on the MITRE website and the Mozilla security advisories.