CVE-2016-5293

Description

When the Mozilla Updater is run, if the Updaters log file in the working directory points to a hardlink, data can be appended to an arbitrary local file. This vulnerability requires local system access. Note: this issue only affects Windows operating systems. This vulnerability affects Firefox ESR < 45.5 and Firefox < 50.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.071

Associated Vulnerability

VulnerabilityOS Platform
Update for Mozilla Firefox ESR (45.5.0)Windows
Update for Mozilla Firefox (50.0)Windows
Update for Mozilla Firefox x64 (50.0)Windows
Update for Mozilla Firefox (50.0.1)Windows
Update for Mozilla Firefox x64 (50.0.1)Windows
Update for Mozilla Firefox (50.0.2)Windows
Update for Mozilla Firefox x64 (50.0.2)Windows
Update for Mozilla Firefox ESR (45.5.1)Windows
Update for Mozilla Firefox (50.1.0)Windows
Update for Mozilla Firefox x64 (50.1.0)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-304312Update for Mozilla Firefox ESR (45.5.0)
PATCH-344482Mozilla Firefox (134.0.1)
PATCH-304314Update for Mozilla Firefox x64 (50.0)
PATCH-344482Mozilla Firefox (134.0.1)
PATCH-304365Update for Mozilla Firefox x64 (50.0.1)
PATCH-344482Mozilla Firefox (134.0.1)
PATCH-304376Update for Mozilla Firefox x64 (50.0.2)
PATCH-304377Update for Mozilla Firefox ESR (45.5.1)
PATCH-344482Mozilla Firefox (134.0.1)
PATCH-304411Update for Mozilla Firefox x64 (50.1.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234