CVE-2016-5255: Use After Free
Last updated 24 July 2024
Other sources
Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows remote attackers to execute arbitrary code via crafted JavaScript that is mishandled during incremental garbage collection.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 137.0.1-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 128.9.0esr-1~deb11u1Fixed in 128.8.0esr-1~deb12u1Fixed in 128.9.0esr-1~deb12u1Fixed in 128.9.0esr-2 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 48.0
Event History
Frequently Asked Questions
What is CVE-2016-5255?
CVE-2016-5255 is a use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before version 48.0.
How does CVE-2016-5255 affect Mozilla Firefox?
CVE-2016-5255 allows remote attackers to execute arbitrary code in Mozilla Firefox through crafted JavaScript that is mishandled during incremental garbage collection.
What is the severity of CVE-2016-5255?
CVE-2016-5255 has a severity score of 8.8 (high severity).
Which versions of Mozilla Firefox are affected by CVE-2016-5255?
Mozilla Firefox versions up to and including 47.0.1 are affected by CVE-2016-5255.
How can I fix CVE-2016-5255 in Mozilla Firefox?
To fix CVE-2016-5255, update Mozilla Firefox to version 48.0 or later.