First published: Fri Aug 05 2016(Updated: )
Last updated 24 July 2024
Credit: security@mozilla.org security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Linux | =5.0 | |
Oracle Linux | =6 | |
Oracle Linux | =7 | |
Mozilla Firefox | <=47.0.1 | |
Mozilla Firefox ESR | =45.1.0 | |
Mozilla Firefox ESR | =45.1.1 | |
Mozilla Firefox ESR | =45.2.0 | |
Mozilla Firefox ESR | =45.3.0 | |
Mozilla Firefox | =45.1.0 | |
Mozilla Firefox | =45.1.1 | |
Mozilla Firefox | =45.2.0 | |
Mozilla Firefox | =45.3.0 | |
debian/firefox | 133.0.3-1 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.5.0esr-1~deb11u1 128.3.1esr-1~deb12u1 128.5.0esr-1~deb12u1 128.5.0esr-1 128.5.1esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5252 is a vulnerability in Mozilla Firefox and Firefox ESR that allows remote attackers to execute arbitrary code via crafted two-dimensional graphics data.
CVE-2016-5252 has a severity rating of 8.8 (high).
Oracle Linux versions 5.0, 6, and 7, Mozilla Firefox versions up to 47.0.1, and Mozilla Firefox ESR versions 45.1.0, 45.1.1, 45.2.0, and 45.3.0 are affected by CVE-2016-5252.
To fix CVE-2016-5252, update Mozilla Firefox to version 48.0 or newer, or update Mozilla Firefox ESR to version 45.3.0 or newer.
More information about CVE-2016-5252 can be found on the CVE website (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5252), Mozilla security advisories (https://www.mozilla.org/en-US/security/advisories/mfsa2016-67/), and Bugzilla (https://bugzilla.mozilla.org/show_bug.cgi?id=1268854).