Oval Definition:oval:com.ubuntu.xenial:def:201652950000000
Revision Date:2018-06-11Version:1
Title:CVE-2016-5295 on Ubuntu 16.04 LTS (xenial) - medium.
Description:This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozilla Updater to run malicious local files. This vulnerability requires local system access and is a variant of MFSA2013-44. Note: this issue only affects Windows operating systems. This vulnerability affects Firefox < 50.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-5295
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND Package Information
  • NOT firefox package in xenial, while related to the CVE in some way, is not affected (note: 'windows only').
  • OR NOT firefox-globalmenu package in xenial, while related to the CVE in some way, is not affected (note: 'windows only').
  • OR NOT firefox-mozsymbols package in xenial, while related to the CVE in some way, is not affected (note: 'windows only').
  • OR NOT firefox-testsuite package in xenial, while related to the CVE in some way, is not affected (note: 'windows only').
  • OR NOT thunderbird package in xenial, while related to the CVE in some way, is not affected (note: 'windows only').
  • OR NOT thunderbird-globalmenu package in xenial, while related to the CVE in some way, is not affected (note: 'windows only').
  • OR NOT thunderbird-gnome-support package in xenial, while related to the CVE in some way, is not affected (note: 'windows only').
  • OR NOT thunderbird-mozsymbols package in xenial, while related to the CVE in some way, is not affected (note: 'windows only').
  • OR NOT xul-ext-calendar-timezones package in xenial, while related to the CVE in some way, is not affected (note: 'windows only').
  • OR NOT xul-ext-gdata-provider package in xenial, while related to the CVE in some way, is not affected (note: 'windows only').
  • OR NOT xul-ext-lightning package in xenial, while related to the CVE in some way, is not affected (note: 'windows only').
  • BACK