First published: Tue Nov 15 2016(Updated: )
Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <45.5 | 45.5 |
<50 | 50 | |
Mozilla Firefox ESR | <45.5 | 45.5 |
Mozilla Firefox | <50.0 | |
Mozilla Firefox ESR | <45.5.0 | |
Mozilla Thunderbird | <45.5.0 | |
Debian Debian Linux | =8.0 | |
debian/firefox | 118.0.2-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2016-5290 is critical.
Mozilla Thunderbird (up to version 45.5), Mozilla Firefox (up to version 50), and Mozilla Firefox ESR (up to version 45.5) are affected by CVE-2016-5290.
To fix CVE-2016-5290, update your Mozilla Thunderbird to version 45.5 or later, update your Mozilla Firefox to version 50 or later, or update your Mozilla Firefox ESR to version 45.5 or later.
You can find more information about CVE-2016-5290 in the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/buglist.cgi?bug_id=1309720%2C1297062%2C1303710%2C1018486%2C1292590%2C1301343%2C1301496%2C1308048%2C1308346%2C1299519%2C1286911%2C1298169), [Mozilla Security Advisory MFSA2016-93](https://www.mozilla.org/en-US/security/advisories/mfsa2016-93/), [Mozilla Security Advisory MFSA2016-89](https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/).