CVE-2016-9079: Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows.
Other sources
Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 118.0.2-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 91.12.0esr-1~deb10u1Fixed in 115.3.1esr-1~deb10u1Fixed in 102.15.0esr-1~deb11u1Fixed in 115.3.1esr-1~deb11u1Fixed in 102.15.1esr-1~deb12u1Fixed in 115.3.0esr-1~deb12u1Fixed in 115.3.0esr-1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 50.0.2 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 45.5.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 45.5.1
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9079?
The severity of CVE-2016-9079 is classified as high due to its potential for exploitation in the wild affecting users.
How do I fix CVE-2016-9079?
To fix CVE-2016-9079, users should update their Firefox, Firefox ESR, or Thunderbird to the latest patched version.
Which software is affected by CVE-2016-9079?
CVE-2016-9079 affects multiple versions of Firefox, Firefox ESR, and Thunderbird, especially those prior to specific fixed versions.
Can CVE-2016-9079 be exploited on all operating systems?
CVE-2016-9079 has been primarily reported to affect users on Windows operating systems.
Is CVE-2016-9079 related to SVG Animation vulnerabilities?
Yes, CVE-2016-9079 is specifically identified as a use-after-free vulnerability in SVG Animation.