CVE-2016-5290: Buffer Overflow
Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
Other sources
Mozilla developers and community members Olli Pettay, Christian Holler, Ehsan Akhgari, Jon Coppeard, Gary Kwong, Tooru Fujisawa, Philipp, and Randell Jesup reported memory safety bugs present in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
— Mozilla
Mozilla developers and community members Olli Pettay, Christian Holler, Ehsan Akhgari, Jon Coppeard, Gary Kwong, Tooru Fujisawa, Philipp, and Randell Jesup reported memory safety bugs present in Thunderbird ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2016-5296
- CVE-2016-5294
- CVE-2016-5297
- CVE-2016-9066
- CVE-2016-5291
- CVE-2016-9074
- CVE-2016-5290
- CVE-2016-5292
- CVE-2016-5293
- CVE-2016-9064
- CVE-2016-9065
- CVE-2016-9067
- CVE-2016-9068
- CVE-2016-9072
- CVE-2016-9075
- CVE-2016-9077
- CVE-2016-5295
- CVE-2016-5298
- CVE-2016-5299
- CVE-2016-9061
- CVE-2016-9062
- CVE-2016-9070
- CVE-2016-9073
- CVE-2016-9076
- CVE-2016-9063
- CVE-2016-9071
- CVE-2016-5289
Frequently Asked Questions
What is the severity of CVE-2016-5290?
The severity of CVE-2016-5290 is critical.
Which software products are affected by CVE-2016-5290?
Mozilla Thunderbird (up to version 45.5), Mozilla Firefox (up to version 50), and Mozilla Firefox ESR (up to version 45.5) are affected by CVE-2016-5290.
How can I fix CVE-2016-5290?
To fix CVE-2016-5290, update your Mozilla Thunderbird to version 45.5 or later, update your Mozilla Firefox to version 50 or later, or update your Mozilla Firefox ESR to version 45.5 or later.
Where can I find more information about CVE-2016-5290?
You can find more information about CVE-2016-5290 in the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/buglist.cgi?bug_id=1309720%2C1297062%2C1303710%2C1018486%2C1292590%2C1301343%2C1301496%2C1308048%2C1308346%2C1299519%2C1286911%2C1298169), [Mozilla Security Advisory MFSA2016-93](https://www.mozilla.org/en-US/security/advisories/mfsa2016-93/), [Mozilla Security Advisory MFSA2016-89](https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/).