Oval Definition:oval:com.ubuntu.xenial:def:20161960000
Revision Date:2016-03-13Version:1
Title:CVE-2016-1960 on Ubuntu 16.04 LTS (xenial) - medium.
Description:Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-1960
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND Package Information
  • NOT While related to the CVE in some way, the 'firefox' package in xenial is not affected (note: '45.0+build2-0ubuntu1').
  • OR The 'thunderbird' package in xenial was vulnerable but has been fixed (note: '1:38.7.2+build1-0ubuntu0.16.04.1').
  • BACK