Red Hat Bugzilla – Bug 1361980
CVE-2016-5254 Mozilla: Use-after-free when using alt key and toplevel menus (MFSA 2016-70)
Last modified: 2016-09-23 01:32:04 EDT
Security researcher Abhishek Arya (Inferno) of the Google Chrome Security Team reported a use-after-free vulnerability when the alt key is used in conjunction with toplevel menu items in Firefox. This results in a potentially exploitable crash when triggered. This vulnerability is mitigated by not being triggerable by web content, only direct user interaction with the keyboard. External Reference: https://www.mozilla.org/security/announce/2016/mfsa2016-70.html Acknowledgements: Name: the Mozilla project Upstream: Abhishek Arya
This issue has been addressed in the following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 7 Via RHSA-2016:1551 https://rhn.redhat.com/errata/RHSA-2016-1551.html