CVE-2016-5258: Use After Free
Last updated 24 July 2024
Other sources
Use-after-free vulnerability in the WebRTC socket thread in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code by leveraging incorrect free operations on DTLS objects during the shutdown of a WebRTC session.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-5258?
CVE-2016-5258 is a use-after-free vulnerability in the WebRTC socket thread in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3.
How severe is CVE-2016-5258?
CVE-2016-5258 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2016-5258?
CVE-2016-5258 affects Oracle Linux 5.0, Oracle Linux 6, Oracle Linux 7, Mozilla Firefox up to version 47.0.1, and Mozilla Firefox ESR versions 45.1.0, 45.1.1, 45.2.0, and 45.3.0.
How can remote attackers exploit CVE-2016-5258?
Remote attackers can exploit CVE-2016-5258 by leveraging incorrect free operations on DTLS objects during the shutdown of a WebRTC session to execute arbitrary code.
Where can I find more information about CVE-2016-5258?
You can find more information about CVE-2016-5258 on the CVE Mitre website, Mozilla's security advisories page, and the Bugzilla entry.