Use-after-free in Mozilla products - CVE-2016-9079
Published: December 1, 2016 / Updated: February 27, 2017
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to use-after-free error when processing SVG animation in nsSMILTimeContainer::NotifyTimeChange() function. A remote attacker can create a specially crafted web page, host malicious SVG file on it and execute arbitrary code on vulnerable system.
Successful exploitation may allow an attacker to gain complete control over vulnerable system.
Note: this vulnerability is being publicly exploited against Tor Browser users.
Affected software
Mozilla Firefox
Mozilla Thunderbird
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
SUSE Linux
Slackware Linux
How to mitigate CVE-2016-9079
Links to Public Exploits and PoC-codes
- Exploit #1890 - CVE-2016-9079 (CVE-2016-9079 exploit code as it appeared on https://lists.torproject.org/pipermail/tor-talk/2016-November/042639.html) (March 18, 2020)
- Exploit #108 - CVE-2016-9079 (A demo exploit of CVE-2016-9079 on Ubuntu x64) (March 18, 2020)
- Exploit #476 - Firefox 50.0.1 - ASM.JS JIT-Spray Remote Code Execution (March 18, 2020)
- Exploit #477 - Mozilla Firefox < 50.0.2 - 'nsSMILTimeContainer::NotifyTimeChange()' Remote Code Execution (Metasploit) (March 18, 2020)
- Exploit #1697 - Firefox nsSMILTimeContainer::NotifyTimeChange() RCE (March 18, 2020)
External References
Related Security Bulletins
- Remote code execution in Mozilla Firefox
- Arch Linux update for thunderbird
- Arch Linux update for thunderbird
- Slackware Linux update for mozilla-thunderbird
- Slackware Linux update for mozilla-firefox
- SUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for Mozilla Thunderbird
- Red Hat update for thunderbird