CVE-2016-9079
firefox-esr - security update
7.5
HIGH
CVSS 3.1
⚠ KEVEPSS 87.6%
描述
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
如何修補 CVE-2016-9079
要修補 CVE-2016-9079,請將受影響套件升級到下列已修補版本。
- —升級至 45.5.1esr-1 或更新版本
- —升級至 45.5.1esr-1~deb8u1 或更新版本
CVE-2016-9079 正在被利用嗎?
是 — CVE-2016-9079 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(2)
- from 0, < 45.5.1esr-1
- from 0, < 45.5.1esr-1~deb8u1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |