CVE-2016-9079
KEV PoC ×3massUse-After-Free in Mozilla Firefox and Tor Browser SVG Animation Exploited in the Wild
CISA: Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability
CVE-2016-9079 is a use-after-free flaw (CWE-416) in the SVG Animation component of Mozilla's Gecko engine, affecting Firefox before 50.0.2, Firefox ESR before 45.5.1, and Thunderbird before 45.5.1, as well as the Firefox-ESR-based Tor Browser and distro-packaged builds on Debian and Red Hat Enterprise Linux. It is triggered when the browser renders SVG content with animations, typically by loading a crafted web page, causing a freed SVG animation object to be reused and corrupting memory. A successful attack can lead to arbitrary code execution in the browser context or disclosure of sensitive memory contents; the assigned CVSS 3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) reflects network-triggered memory corruption with high confidentiality impact and no privileges required. The in-the-wild exploit observed at disclosure targeted Firefox and Tor Browser users on Windows. The flaw has public PoC exploits, carries an EPSS 30-day exploitation probability of 87.4% (100th percentile), and was added to the CISA KEV catalog on 2023-06-22 with a required action to apply vendor updates.
What to do: Upgrade Firefox to 50.0.2 or later, Firefox ESR to 45.5.1 or later, and Thunderbird to 45.5.1 or later, and install the corresponding patched Tor Browser build; users on Windows were the observed in-the-wild targets, so prioritize those hosts. On Debian and Red Hat Enterprise Linux, apply the vendor's updated firefox/thunderbird/tor packages per their advisories, consistent with the CISA KEV required action. As an interim mitigation, restrict loading of untrusted web content with animated SVG and verify no machines in the environment are still running Firefox versions older than 50.0.2.
| mozilla Firefox | < 50.0.2 |
| mozilla Firefox ESR | < 45.5.1 |
| mozilla Thunderbird | < 45.5.1 |
| torproject tor (Tor Browser, Firefox ESR-based) | builds based on Firefox ESR < 45.5.1; exact Tor Browser version not specified in source data |
| Debian Linux (firefox, thunderbird, tor packages) | — |
| redhat Red Hat Enterprise Linux (Server, Server AUS, Server EUS, Desktop, Workstation; firefox/thunderbird packages) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
- Affected
- Mozilla Firefox, Firefox ESR, and Thunderbird
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- debianredhatmozillatorproject
- Products
- debian linux, enterprise linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux workstation, thunderbird, firefox, tor
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N