CVE-2016-9893: Buffer Overflow
Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Other sources
Mozilla developers and community members Jan de Mooij, Iris Hsiao, Christian Holler, Carsten Book, Timothy Nikkel, Christoph Diehl, Olli Pettay, Raymond Forbes, and Boris Zbarsky reported memory safety bugs present in Firefox 50.0.2 and Firefox ESR 45.5.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
— Mozilla
Mozilla developers and community members Jan de Mooij, Iris Hsiao, Christian Holler, Carsten Book, Timothy Nikkel, Christoph Diehl, Olli Pettay, Raymond Forbes, and Boris Zbarsky reported memory safety bugs present in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
Mozilla developers and community members Jan de Mooij, Iris Hsiao, Christian Holler, Carsten Book, Timothy Nikkel, Christoph Diehl, Olli Pettay, Raymond Forbes, Boris Zbarsky, and Marco Castelluccio reported memory safety bugs present in Firefox 50.0.2 and Firefox ESR 45.5.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2016-9893?
CVE-2016-9893 has been classified as a moderate severity vulnerability due to its potential for memory corruption and arbitrary code execution.
How do I fix CVE-2016-9893?
To fix CVE-2016-9893, users should update their software to the latest versions: Firefox 50.1 or later, Firefox ESR 45.6 or later, and Thunderbird 45.6 or later.
Which software is affected by CVE-2016-9893?
CVE-2016-9893 affects Firefox versions prior to 50.1, Firefox ESR versions prior to 45.6, and Thunderbird versions prior to 45.6.
Can CVE-2016-9893 lead to full system compromise?
While CVE-2016-9893 involves memory safety bugs, it has the potential to be exploited to run arbitrary code, which could lead to a partial system compromise.
Is there a workaround for CVE-2016-9893?
There is no known effective workaround for CVE-2016-9893, so the best course of action is to update to the fixed versions as soon as possible.