CVE-2016-5294: Input Validation
The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulnerability requires local system access. Note: this issue only affects Windows operating systems.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2016-5296
- CVE-2016-5294
- CVE-2016-5297
- CVE-2016-9066
- CVE-2016-5291
- CVE-2016-9074
- CVE-2016-5290
- CVE-2016-5292
- CVE-2016-5293
- CVE-2016-9064
- CVE-2016-9065
- CVE-2016-9067
- CVE-2016-9068
- CVE-2016-9072
- CVE-2016-9075
- CVE-2016-9077
- CVE-2016-5295
- CVE-2016-5298
- CVE-2016-5299
- CVE-2016-9061
- CVE-2016-9062
- CVE-2016-9070
- CVE-2016-9073
- CVE-2016-9076
- CVE-2016-9063
- CVE-2016-9071
- CVE-2016-5289
Frequently Asked Questions
What is CVE-2016-5294?
CVE-2016-5294 is a vulnerability in the Mozilla Updater that allows an attacker to choose an arbitrary target working directory for output files during the update process.
Which operating systems are affected by CVE-2016-5294?
This vulnerability only affects Windows operating systems.
Which software versions are affected by CVE-2016-5294?
Mozilla Thunderbird up to version 45.5, Mozilla Firefox up to version 50, and Mozilla Firefox ESR up to version 45.5 are affected by this vulnerability.
How severe is CVE-2016-5294?
CVE-2016-5294 has a severity rating of 7 out of 10 (high severity).
How can CVE-2016-5294 be fixed?
To fix CVE-2016-5294, users should update to the latest versions of Mozilla Thunderbird, Mozilla Firefox, or Mozilla Firefox ESR, which have the necessary patches to address this vulnerability.