Mozilla Foundation Security Advisory 2016-33
Use-after-free in GetStaticInstance in WebRTC
- Announced
- March 8, 2016
- Reporter
- Ronald Crane
- Impact
- High
- Products
- Firefox
- Fixed in
-
- Firefox 45
Description
Security researcher Ronald Crane reported a race condition in
GetStaticInstance
in WebRTC which results in a use-after-free. This could
result in a potentially exploitable crash. This issue was found through code inspection
and does not have clear mechanism to be exploited through web content but is vulnerable if
a mechanism can be found to trigger it.