CVE-2016-5271: Medium severity firefox vulnerability
An out-of-bounds read during the processing of text runs in some pages using display:contents.
Other sources
The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via text runs in conjunction with a "display: contents" Cascading Style Sheets (CSS) property.
— Launchpad
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2016-5271?
CVE-2016-5271 is a vulnerability that allows remote attackers to cause a denial of service (application crash) via text runs in conjunction with the "display: contents" CSS property in Mozilla Firefox before version 49.0.
What is the severity of CVE-2016-5271?
The severity of CVE-2016-5271 is rated as medium with a score of 6.5.
How does CVE-2016-5271 affect Mozilla Firefox?
CVE-2016-5271 affects Mozilla Firefox versions before 49.0.
How can I fix CVE-2016-5271?
To fix CVE-2016-5271, users should update to Mozilla Firefox version 49.0 or higher.
Where can I find more information about CVE-2016-5271?
You can find more information about CVE-2016-5271 at the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1288946), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2016-85/), and [Mozilla Security Announce](http://www.mozilla.org/security/announce/2016/mfsa2016-85.html).