CVE-2016-1972
published 2016-03-13CVE-2016-1972: Race condition in libvpx in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (use-after-free) or possibly have…
PriorityP336high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.91%
77.7th percentile
Race condition in libvpx in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvpx | — | — |
| mozilla | firefox | <= 44.0.2 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: WebRTC and LibVPX vulnerabilities found through code inspection (MFSA 2016-32)
vendor_redhat·2016-03-08·CVSS 8.8
CVE-2016-1972 [HIGH] Mozilla: WebRTC and LibVPX vulnerabilities found through code inspection (MFSA 2016-32)
Mozilla: WebRTC and LibVPX vulnerabilities found through code inspection (MFSA 2016-32)
Race condition in libvpx in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 7) - Not
Debian
CVE-2016-1972: libvpx - Race condition in libvpx in Mozilla Firefox before 45.0 on Windows might allow r...
vendor_debian·2016·CVSS 8.8
CVE-2016-1972 [HIGH] CVE-2016-1972: libvpx - Race condition in libvpx in Mozilla Firefox before 45.0 on Windows might allow r...
Race condition in libvpx in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-cx3x-8cg7-v23q: Race condition in libvpx in Mozilla Firefox before 45
ghsa_unreviewed·2022-05-17
CVE-2016-1972 [HIGH] GHSA-cx3x-8cg7-v23q: Race condition in libvpx in Mozilla Firefox before 45
Race condition in libvpx in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7031 ceph: RGW permits bucket listing when authenticated_users=read
bugzilla·2016-09-01·CVSS 7.5
CVE-2016-7031 [HIGH] CVE-2016-7031 ceph: RGW permits bucket listing when authenticated_users=read
CVE-2016-7031 ceph: RGW permits bucket listing when authenticated_users=read
Description of problem:
An anonymous S3 user may be able to (incorrectly) list the contents of a bucket which has an authenticated_users=read ACL.
Version-Release number of selected component (if applicable):
1.3.x
Additional info:
This issue corresponds to upstream tracker issue
http://tracker.ceph.com/issues/13207
Fixed on master in
https://github.com/ceph/ceph/pull/6057
Discussion:
This issue has been addressed in the following products:
Red Hat Ceph Storage 1.3 for RHEL 7
Via RHSA-2016:1972 https://rhn.redhat.com/errata/RHSA-2016-1972.html
---
This issue has been addressed in the following products:
Red Hat Ceph Storage 1.3 for Ubuntu
Via RHSA-2016:1973 https://rhn.redhat.com/errata/RHSA-2016-19
Bugzilla
CVE-2016-1970 CVE-2016-1971 CVE-2016-1972 CVE-2016-1975 CVE-2016-1976 Mozilla: WebRTC and LibVPX vulnerabilities found through code inspection (MFSA 2016-32)
bugzilla·2016-03-08·CVSS 8.8
CVE-2016-1970 [HIGH] CVE-2016-1970 CVE-2016-1971 CVE-2016-1972 CVE-2016-1975 CVE-2016-1976 Mozilla: WebRTC and LibVPX vulnerabilities found through code inspection (MFSA 2016-32)
CVE-2016-1970 CVE-2016-1971 CVE-2016-1972 CVE-2016-1975 CVE-2016-1976 Mozilla: WebRTC and LibVPX vulnerabilities found through code inspection (MFSA 2016-32)
Security researcher Ronald Crane reported five moderate rated vulnerabilities affecting released code that were found through code inspection. These included the following issues in WebRTC: an integer underflow, a missing status check, race condition, and a use of deleted pointers to create new object. A race condition in LibVPX was also identified. These do not all have clear mechanisms to be exploited through web content but are vulnerable if a mechanism can be found to trigger them.
External Reference:
https://www.mozilla.org/security/announce/2016/mfsa2016-32.html
Acknowledgements:
Name: the Mozilla project
Upstream: Ronald
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00031.htmlhttp://www.mozilla.org/security/announce/2016/mfsa2016-32.htmlhttp://www.securityfocus.com/bid/84220http://www.securitytracker.com/id/1035215https://bugzilla.mozilla.org/show_bug.cgi?id=1218124https://security.gentoo.org/glsa/201605-06http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00031.htmlhttp://www.mozilla.org/security/announce/2016/mfsa2016-32.htmlhttp://www.securityfocus.com/bid/84220http://www.securitytracker.com/id/1035215https://bugzilla.mozilla.org/show_bug.cgi?id=1218124https://security.gentoo.org/glsa/201605-06
2016-03-13
Published