vendor:
Firefox
by:
Geeknik Labs
5,5
CVSS
MEDIUM
Stack Overflow DoS
119
CWE
Product Name: Firefox
Affected Version From: 50
Affected Version To: 55
Patch Exists: Yes
Related CWE: N/A
CPE: Mozilla:Firefox
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2016
Unpatched Mozilla Firefox v50 – v55 Stack Overflow DoS Vulnerability
A stack overflow DoS vulnerability affecting Firefox versions 50 through 55 was discovered by Geeknik Labs. This flaw does NOT affect ESR 45 or the latest version of the Tor Browser Bundle. This flaw can be triggered by simply visiting a website with the PoC code embedded in it and requires no further user interaction nor does it require any special privileges. Successful exploitation results in the browser tab crashing.
Mitigation:
Update to the latest version of Firefox.