First published: Wed Nov 30 2016(Updated: )
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 118.0.2-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 | |
Firefox | <50.0.2 | 50.0.2 |
Firefox ESR | <45.5.1 | 45.5.1 |
Thunderbird | <45.5.1 | 45.5.1 |
Mozilla Thunderbird | ||
Debian Linux | =9.0 | |
Red Hat Enterprise Linux | =5.0 | |
Red Hat Enterprise Linux | =6.0 | |
Red Hat Enterprise Linux | =7.0 | |
Red Hat Enterprise Linux Desktop | =5.0 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server | =5.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.3 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =7.3 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =7.5 | |
Red Hat Enterprise Linux Workstation | =5.0 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Workstation | =7.0 | |
All of | ||
Thunderbird | <45.5.1 | |
Microsoft Windows Operating System | ||
All of | ||
Firefox | <50.0.2 | |
Microsoft Windows Operating System | ||
All of | ||
Firefox | <45.5.1 | |
Microsoft Windows Operating System | ||
All of | ||
Tor Project Tor | ||
Microsoft Windows Operating System | ||
Thunderbird | <45.5.1 | |
Microsoft Windows Operating System | ||
Firefox | <50.0.2 | |
Firefox ESR | <45.5.1 | |
Tor Project Tor |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-9079 is classified as high due to its potential for exploitation in the wild affecting users.
To fix CVE-2016-9079, users should update their Firefox, Firefox ESR, or Thunderbird to the latest patched version.
CVE-2016-9079 affects multiple versions of Firefox, Firefox ESR, and Thunderbird, especially those prior to specific fixed versions.
CVE-2016-9079 has been primarily reported to affect users on Windows operating systems.
Yes, CVE-2016-9079 is specifically identified as a use-after-free vulnerability in SVG Animation.