CVE-2016-5258
Summary
| CVE | CVE-2016-5258 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-08-05 01:59:00 UTC |
| Updated | 2019-12-27 16:08:00 UTC |
| Description | Use-after-free vulnerability in the WebRTC socket thread in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code by leveraging incorrect free operations on DTLS objects during the shutdown of a WebRTC session. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Mozilla Firefox Multiple Security Vulnerabilities |
BID |
www.securityfocus.com |
|
| [security-announce] openSUSE-SU-2016:1964-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| [security-announce] openSUSE-SU-2016:2026-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| Mozilla Firefox, Thunderbird: Multiple vulnerabilities (GLSA 201701-15) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Oracle Linux Bulletin - July 2016 |
CONFIRM |
www.oracle.com |
Third Party Advisory |
| USN-3044-1: Firefox vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| 1279146 - (CVE-2016-5258) WebRTC - Use After Free in socket thread |
CONFIRM |
bugzilla.mozilla.org |
Exploit, Issue Tracking |
| Use-after-free in DTLS during WebRTC session shutdown — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Debian -- Security Information -- DSA-3640-1 firefox-esr |
DEBIAN |
www.debian.org |
|
| Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Bypass Security Restrictions, Spoof Content, Modify Files, and Obtain Potentially Sensitive Information - SecurityTracker |
SECTRACK |
www.securitytracker.com |
|
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710500 Gentoo Linux Mozilla Firefox, Thunderbird Multiple Vulnerabilities (GLSA 201701-15)