Vulnerability CVE-2016-1956


Published: 2016-03-13

Description:
Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.

Type:

CWE-399

(Resource Management Errors)

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.1/10
6.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete
Affected software
Opensuse -> LEAP 
Opensuse -> Opensuse 
Novell -> Suse package hub for suse linux enterprise 
Novell -> LEAP 
Novell -> Opensuse 
Mozilla -> Firefox 

 References:
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00029.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00031.html
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00007.html
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00008.html
http://www.mozilla.org/security/announce/2016/mfsa2016-19.html
http://www.securitytracker.com/id/1035215
http://www.ubuntu.com/usn/USN-2917-1
http://www.ubuntu.com/usn/USN-2917-2
http://www.ubuntu.com/usn/USN-2917-3
https://bugzilla.mozilla.org/show_bug.cgi?id=1199923
https://security.gentoo.org/glsa/201605-06

Copyright 2024, cxsecurity.com

 

Back to Top