A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN packets in a short period of time due to a lack of rate limiting being applied on e10s systems, allowing for a denial of service attack. This vulnerability affects Firefox < 51.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 11, 2018 |
| Freebsd | — | Upgrade libxulUpgrade linux-thunderbirdUpgrade linux-firefoxUpgrade firefoxUpgrade thunderbirdUpgrade seamonkeyUpgrade firefox-esrUpgrade linux-seamonkey | Jan 25, 2017 | Jan 24, 2017 |
| Mfsa2017 01 | — | Upgrade to Mozilla Firefox version 51.0 | Jul 12, 2018 | Jun 11, 2018 |
| Suse | — | Upgrade mozillafirefox-translations-commonUpgrade mozillafirefox-translations-otherUpgrade mozillafirefox-develUpgrade mozillafirefox | Feb 2, 2017 | Jan 24, 2017 |
| Ubuntu | — | Upgrade firefox | Jan 28, 2017 | Jan 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub