Mozilla Foundation Security Advisory 2016-87

Security vulnerabilities fixed in Firefox 49.0.2

Announced
October 20, 2016
Impact
high
Products
Firefox
Fixed in
  • Firefox 49.0.2

#CVE-2016-5287: Crash in nsTArray_base<T>::SwapArrayElements

Reporter
Philipp
Impact
high
Description

A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefox 49.

References

#CVE-2016-5288: Web content can read cache entries

Reporter
Developers at Cliqz.com
Impact
high
Description

A Cliqz.com developer demonstrated that web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49.

References