PT-2016-1454 · Mozilla+3 · Firefox+3

Oriol

+1

·

Publicado

2016-03-08

·

Atualizado

2024-12-12

·

CVE-2016-1963

CVSS v3.1

7.4

Alta

VetorAV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 45.0
Description The issue is related to the FileReader class in Mozilla Firefox, which has insufficient access control. This can be exploited by a local attacker to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.
Recommendations For versions prior to 45.0, update to version 45.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the FileReader API until a patch is available.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1277
ALT-PU-2016-1454
BDU:2016-00755
CVE-2016-1963
OPENSUSE-SU-2016_0731-1
OPENSUSE-SU-2016_0733-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
USN-2917-1
USN-2917-2
USN-2917-3

Produtos afetados

Alt Linux
Firefox
Suse
Ubuntu