SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Web Browser)  >   Mozilla Firefox Vendors:   Mozilla.org
Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
SecurityTracker Alert ID:  1035215
SecurityTracker URL:  http://securitytracker.com/id/1035215
CVE Reference:   CVE-2016-1950, CVE-2016-1952, CVE-2016-1953, CVE-2016-1954, CVE-2016-1955, CVE-2016-1956, CVE-2016-1957, CVE-2016-1958, CVE-2016-1959, CVE-2016-1960, CVE-2016-1961, CVE-2016-1962, CVE-2016-1963, CVE-2016-1964, CVE-2016-1965, CVE-2016-1966, CVE-2016-1967, CVE-2016-1968, CVE-2016-1969, CVE-2016-1970, CVE-2016-1971, CVE-2016-1972, CVE-2016-1973, CVE-2016-1974, CVE-2016-1975, CVE-2016-1976, CVE-2016-1977, CVE-2016-1979, CVE-2016-2790, CVE-2016-2791, CVE-2016-2792, CVE-2016-2793, CVE-2016-2794, CVE-2016-2795, CVE-2016-2796, CVE-2016-2797, CVE-2016-2798, CVE-2016-2799, CVE-2016-2800, CVE-2016-2801, CVE-2016-2802   (Links to External Site)
Updated:  Mar 14 2016
Original Entry Date:  Mar 9 2016
Impact:   Denial of service via network, Execution of arbitrary code via network, Modification of system information, Modification of user information, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): prior to 45.0
Description:   Multiple vulnerabilities were reported in Mozilla Firefox. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can cause denial of service conditions on the target system. A remote user can modify files on the target system. A remote user can bypass same-origin restrictions on the target system. A remote user can spoof the address bar.

A remote user can create specially crafted content that, when loaded by the target user, will execute arbitrary code on the target user's system [CVE-2016-1952, CVE-2016-1953].

A remote user can create specially crafted HTML that, when loaded by the target user, will overwrite files on the target user's system with a Content Security Policy (CSP) violation report [CVE-2016-1954].

A remote user may be able to obtain full path information for cross-origin iframe navigations in a CSP violatin report [CVE-2016-1955].

A remote user can create content that, when loaded by the target user, will perform certain WebGL operations in a canvas to consume excessive memory resources on the target user's system [CVE-2016-1956]. Certain Intel drivers on Linux are affected.

A remote user can create a specially crafted MPEG4 video file that, when loaded by the target user, will trigger a memory leak in the libstagefright library [CVE-2016-1957].

A remote user can spoof the address bar URL [CVE-2016-1958].

A remote user can trigger a flaw in the Clients API in Service Workers to cause an out-of-bounds read in ServiceWorkerManager and potentially execute arbitrary code [CVE-2016-1959].

A remote user can trigger a use-after-free memory error in the HTML5 string parser and potentially execute arbitrary code [CVE-2016-1960].

A remote user can trigger a use-after-free memory error in the SetBody function of HTMLDocument and potentially execute arbitrary code [CVE-2016-1961].

A remote user can trigger a use-after-free memory error when using multiple WebRTC data channel connections and potentially execute arbitrary code [CVE-2016-1962].

A local user can modify a file being read by FileReader to potentially execute arbitrary code [CVE-2016-1963].

A remote user can trigger a use-after-free memory error during XML transformation operations and potentially execute arbitrary code [CVE-2016-1964].

A remote user can spoof the address bar using location.protocol and history.back [CVE-2016-1965].

A remote user may be able to read cross-origin URLs [CVE-2016-1967].

A remote user can trigger a buffer overflow in the Brotli library and potentially execute arbitrary code [CVE-2016-1968].

A remote user can trigger a pointer dereference in the Netscape Plugin Application Programming Interface (NPAPI) plug-in and potentially execute arbitrary code [CVE-2016-1966].

A remote user can trigger memory errors in WebRTC and potentially execute arbitrary code [CVE-2016-1970, CVE-2016-1971, CVE-2016-1975, CVE-2016-1976, CVE-2016-1972].

A remote user can trigger a race condition in WebRTC in GetStaticInstance() and potentially execute arbitrary code [CVE-2016-1973].

A remote user can trigger an out-of-bounds memory read error in parsing unicode strings and potentially execute arbitrary code [CVE-2016-1974].

A remote user can create a specially crafted ASN.1 encoded certificate that, when parsed by the Network Security Services (NSS) library, will trigger a heap overflow and potentially execute arbitrary code [CVE-2016-1950].

A remote user can trigger a use-after-free memory error in the NSS libraries when processing DER-encoded keys [CVE-2016-1979].

A remote user can create a specially crafted graphite font that, when loaded by the target user, will trigger a stack corruption, uninitialized memory, out-of-bounds read, or out-of-bounds write error and potentially execute arbitrary code [CVE-2016-1969, CVE-2016-1977, CVE-2016-2790, CVE-2016-2791, CVE-2016-2792, CVE-2016-2793, CVE-2016-2794, CVE-2016-2795, CVE-2016-2796, CVE-2016-2797, CVE-2016-2798, CVE-2016-2799, CVE-2016-2800, CVE-2016-2801, CVE-2016-2802].

Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel Holbert, Jesse Ruderman, Randell Jesup, Carsten Book, Gian-Carlo Pascutto, Tyson Smith, Andrea Marchesini, Jukka Jylanki, Nicolas Golubovic, Muneaki Nishimura (nishimunea) of Recruit Technologies Co.,Ltd., Ucha Gobejishvili, Jose Martinez, Romina Santillan,
Abdulrahman Alqabandi, Looben Yang, ca0nguyen (via HP's Zero Day Initiative), lokihardt (via HP's Zero Day Initiative), Dominique Hazael-Massieux, Oriol, Nicolas Gregoire, Tsubasa Iinuma, Jordi Chancel, Luke Li, the Communications Electronics Security Group (UK) of the GCHQ, Ronald Crane, Francis Gabriel, Tim Taubert, Holger Fuhrmannek, and James Clawson reported these vulnerabilities.

Impact:   A remote user can create content that, when loaded by the target user, will execute arbitrary code on the target user's system.

A remote user can cause denial of service conditions.

A remote user can overwrite files on the target system.

A remote user can bypass same-origin restrictions on the target system.

A remote user can spoof the address bar.

Solution:   The vendor has issued a fix (ESR 38.7; 45.0).

The vendor's advisories are available at:

https://www.mozilla.org/en-US/security/advisories/mfsa2016-16/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-17/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-18/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-19/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-20/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-21/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-22/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-23/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-24/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-25/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-26/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-27/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-28/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-29/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-30/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-31/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-32/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-33/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-34/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-35/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-36/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-37/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-38/

Vendor URL:  www.mozilla.org/en-US/security/advisories/mfsa2016-16/ (Links to External Site)
Cause:   Access control error, Input validation error
Underlying OS:  Linux (Any), UNIX (Any), Windows (Any)

Message History:   This archive entry has one or more follow-up message(s) listed below.
Mar 9 2016 (Red Hat Issues Fix for Network Security Services (NSS)) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Red Hat has issued a fix for Network Security Services (NSS) for Red Hat Enterprise Linux 5.
Mar 9 2016 (Red Hat Issues Fix for Network Security Services (NSS)) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Red Hat has issued a fix for Network Security Services (NSS) for Red Hat Enterprise Linux 6 and 7.
Mar 9 2016 (Red Hat Issues Fix) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Red Hat has issued a fix for Red Hat Enterprise Linux 5, 6, and 7.
Mar 9 2016 (Ubuntu Issues Fix) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Ubuntu has issued a fix for Ubuntu Linux 12.04 LTS, 14.04 LTS, and 15.10.
Mar 9 2016 (CentOS Issues Fix) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
CentOS has issued a fix for CentOS 5 and 6.
Mar 9 2016 (Oracle Issues Fix for Oracle Linux for Network Security Services (NSS)) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Oracle has issued a fix for Network Security Services (NSS) for Oracle Linux 5.
Mar 16 2016 (Red Hat Issues Fix for Mozilla Thunderbird) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Red Hat has issued a fix for Mozilla Thunderbird for Red Hat Enterprise Linux 5, 6, and 7.
Mar 16 2016 (CentOS Issues Fix for Mozilla Thunderbird) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
CentOS has issued a fix for Mozilla Thunderbird for CentOS 7.
Mar 17 2016 (CentOS Issues Fix for Mozilla Thunderbird) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
CentOS has issued a fix for Mozilla Thunderbird for CentOS 5 and 6.
Mar 17 2016 (Oracle Issues Fix for Oracle Linux for Mozilla Thunderbird) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Oracle has issued a fix for Mozilla Thunderbird for Oracle Linux 6 and 7.
Mar 23 2016 (Red Hat Issues Fix for Network Security Services (NSS)) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Red Hat has issued a fix for Network Security Services (NSS) for Red Hat Enterprise Linux 6.2, 6.4, 6.5, 6.6, and 7.1.
Apr 5 2016 (Red Hat Issues Fix for Network Security Services (NSS)) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Red Hat has issued a fix for Network Security Services (NSS) for Red Hat Enterprise Linux 6.
Apr 5 2016 (CentOS Issues Fix for Netscape Portable Runtime API) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
CentOS has issued a fix for Netscape Portable Runtime API for CentOS 6.
Apr 5 2016 (CentOS Issues Fix for Network Security Services (NSS)) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
CentOS has issued a fix for Network Security Services (NSS) for CentOS 6.
Apr 6 2016 (Oracle Issues Fix for Oracle Linux for Network Security Services (NSS)) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Oracle has issued a fix for Network Security Services (NSS) for Oracle Linux 6.
Apr 25 2016 (Red Hat Issues Fix for Network Security Services (NSS)) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Red Hat has issued a fix for Network Security Services (NSS) for Red Hat Enterprise Linux 5.
Apr 25 2016 (Red Hat Issues Fix for Network Security Services (NSS)) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Red Hat has issued a fix for Network Security Services (NSS) for Red Hat Enterprise Linux 7.
Apr 26 2016 (Oracle Issues Fix for NSS for Oracle Linux) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Oracle has issued a fix for Network Security Services (NSS) for Oracle Linux 5 and 7.
Apr 26 2016 (CentOS Issues Fix for Network Security Services (NSS)) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
CentOS has issued a fix for Network Security Services (NSS) for CentOS 5.
Apr 26 2016 (CentOS Issues Fix for Netscape Portable Runtime API) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
CentOS has issued a fix for Netscape Portable Runtime API for CentOS 5 and 7.
Apr 26 2016 (CentOS Issues Fix for Network Security Services (NSS)) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
CentOS has issued a fix for Network Security Services (NSS) for CentOS 7.
Apr 28 2016 (Ubuntu Issues Fix for Mozilla Thunderbird) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Ubuntu has issued a fix for Mozilla Thunderbird for Ubuntu Linux 12.04 LTS, 14.04 LTS, 15.10, and 16.04 LTS.
May 19 2016 (Ubuntu Issues Fix for Mozilla Thunderbird) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Ubuntu has issued a fix for Mozilla Thunderbird for Ubuntu Linux 12.04 LTS, 14.04 LTS, 15.10, and 16.04 LTS.
Jul 8 2016 (IBM Issues Fix for IBM Security Identity Manager Virtual Appliance) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
IBM has issued a fix for IBM Security Identity Manager Virtual Appliance.
Jul 21 2016 (IBM Issues Fix for IBM Security Access Manager) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
IBM has issued a fix for IBM Security Access Manager.
Jul 21 2016 (IBM Issues Fix for IBM Security Access Manager) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
IBM has issued a fix for IBM Security Access Manager.
Oct 19 2016 (Oracle Issues Fix for Sun GlassFish Enterprise Server) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Oracle has issued a fix for Sun GlassFish Enterprise Server.
Oct 19 2016 (Oracle Issues Fix for Sun Java Web Proxy Server) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
Oracle has issued a fix for Sun Java Web Proxy Server (Oracle iPlanet Web Proxy Server).



 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2019, SecurityGlobal.net LLC