CVE-2016-5294 PUBLISHED

Reported by mozilla · Published June 11, 2018

The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulnerability requires local system access. Note: this issue only affects Windows operating systems. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

Affected Products

VendorProductVersions
MozillaThunderbirdunspecified
MozillaFirefox ESRunspecified
MozillaFirefoxunspecified
MozillaFirefox ESRunspecified
MozillaThunderbirdunspecified
MozillaFirefoxunspecified

Timeline

References

Open in Interactive Console →