Confirmed as exploited
CVE-2016-9079
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
01 / ACTION
Required action
Apply updates per vendor instructions.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows.
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
05 / REFERENCES
Further evidence
- http://rhn.redhat.com/errata/RHSA-2016-2843.html
- http://rhn.redhat.com/errata/RHSA-2016-2850.html
- http://www.securityfocus.com/bid/94591
- http://www.securitytracker.com/id/1037370
- https://bugzilla.mozilla.org/show_bug.cgi?id=1321066
- https://security.gentoo.org/glsa/201701-15
- https://security.gentoo.org/glsa/201701-35
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-9079
- https://www.debian.org/security/2016/dsa-3730
- https://www.exploit-db.com/exploits/41151/
- https://www.exploit-db.com/exploits/42327/
- https://www.mozilla.org/security/advisories/mfsa2016-92/