PublicDateAtUSN: 2016-10-25 Candidate: CVE-2016-5287 PublicDate: 2018-06-11 21:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5287 https://hg.mozilla.org/mozilla-central/rev/e62579becf83 https://ubuntu.com/security/notices/USN-3111-1 Description: A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefox 49. This vulnerability affects Firefox < 49.0.2. Ubuntu-Description: Notes: sbeattie> firefox 49 contains commit that introduced issue Bugs: https://bugzilla.mozilla.org/show_bug.cgi?id=1309823 Priority: medium Discovered-by: Assigned-to: chrisccoulson CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_firefox: upstream_firefox: released (49.0.2) precise_firefox: released (49.0.2+build2-0ubuntu0.12.04.1) trusty_firefox: released (49.0.2+build2-0ubuntu0.14.04.1) trusty/esm_firefox: DNE (trusty was released [49.0.2+build2-0ubuntu0.14.04.1]) vivid/ubuntu-core_firefox: DNE vivid/stable-phone-overlay_firefox: DNE xenial_firefox: released (49.0.2+build2-0ubuntu0.16.04.2) esm-infra/xenial_firefox: released (49.0.2+build2-0ubuntu0.16.04.2) yakkety_firefox: released (49.0.2+build2-0ubuntu0.16.10.2) devel_firefox: released (50.0.2+build1-0ubuntu1) Patches_thunderbird: Priority_thunderbird: low upstream_thunderbird: not-affected precise_thunderbird: not-affected trusty_thunderbird: not-affected trusty/esm_thunderbird: DNE (trusty was not-affected) vivid/ubuntu-core_thunderbird: DNE vivid/stable-phone-overlay_thunderbird: DNE xenial_thunderbird: not-affected esm-infra/xenial_thunderbird: not-affected yakkety_thunderbird: not-affected devel_thunderbird: not-affected