CVE-2016-5293: Input Validation
When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local file. This vulnerability requires local system access. Note: this issue only affects Windows operating systems.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2016-5296
- CVE-2016-5292
- CVE-2016-5293
- CVE-2016-5294
- CVE-2016-5297
- CVE-2016-9064
- CVE-2016-9065
- CVE-2016-9066
- CVE-2016-9067
- CVE-2016-9068
- CVE-2016-9072
- CVE-2016-9075
- CVE-2016-9077
- CVE-2016-5291
- CVE-2016-5295
- CVE-2016-5298
- CVE-2016-5299
- CVE-2016-9061
- CVE-2016-9062
- CVE-2016-9070
- CVE-2016-9073
- CVE-2016-9074
- CVE-2016-9076
- CVE-2016-9063
- CVE-2016-9071
- CVE-2016-5289
- CVE-2016-5290
Frequently Asked Questions
What is CVE-2016-5293?
CVE-2016-5293 is a vulnerability that allows data to be appended to an arbitrary local file when the Mozilla Updater is run on Windows operating systems.
How does CVE-2016-5293 affect the Mozilla Firefox browser?
CVE-2016-5293 affects Mozilla Firefox versions up to and excluding 50.
How does CVE-2016-5293 affect the Mozilla Firefox ESR browser?
CVE-2016-5293 affects Mozilla Firefox ESR versions up to and excluding 45.5.
Is local system access required to exploit CVE-2016-5293?
Yes, local system access is required to exploit CVE-2016-5293.
Where can I find more information about CVE-2016-5293?
You can find more information about CVE-2016-5293 at the following references:<br>- [Bugzilla - CVE-2016-5293](https://bugzilla.mozilla.org/show_bug.cgi?id=1246945)<br>- [Mozilla Security Advisory - MFSA2016-89](https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/)<br>- [Mozilla Security Advisory - MFSA2016-90](https://www.mozilla.org/en-US/security/advisories/mfsa2016-90/)