CVE-2016-5294

MEDIUM

Firefox < 45.5.0 and Thunderbird < 45.5.0 - Arbitrary File Write via Updater Working Directory

Title source: llm
STIX 2.1

Description

The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulnerability requires local system access. Note: this issue only affects Windows operating systems. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

References (7)

Core 7
Core References
Exploit, Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1246972
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037298
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201701-15
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94336
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2016-93/
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2016-89/
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2016-90/

Scores

CVSS v3 5.5
EPSS 0.0007
EPSS Percentile 21.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-20
Status published
Products (2)
mozilla/firefox < 45.5.0
mozilla/thunderbird < 45.5.0
Published Jun 11, 2018
Tracked Since Feb 18, 2026