UBUNTU-CVE-2016-5270
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-5270
UBUNTU-CVE-2016-5270
Summary:
Details: Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to cause a denial of service (boolean out-of-bounds write) or possibly have unspecified other impact via Unicode characters that are mishandled during text conversion.
References: https://ubuntu.com/security/CVE-2016-5270, https://www.mozilla.org/en-US/security/advisories/mfsa2016-85/, https://ubuntu.com/security/notices/USN-3076-1, https://ubuntu.com/security/notices/USN-3112-1, https://www.cve.org/CVERecord?id=CVE-2016-5270
Affected packages
Package
Name: firefox
Purl: pkg:deb/ubuntu/[email protected]+build4-0ubuntu0.14.04.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
