Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Ubuntu 11.04 USN-1222-1 Moderate: Memory Vulnerabilities in Firefox

ubuntu
Calendar Grey September 30, 2011
Scroller Ubuntu
Various security issues in Firefox on Ubuntu 11.04 may result in system crashes and potential code execution threats. It is recommended to perform an update.
Firefox could be made to crash or possibly run programs as your login if it opened a malicious website.

Summary

Firefox could be made to crash or possibly run programs as your login if it

opened a malicious website.

Software Description:

- firefox: Mozilla Open Source web browser

Details:

Benjamin Smedberg, Bob Clary, Jesse Ruderman, Bob Clary, Andrew McCreight,

Andreas Gal, Gary Kwong, Igor Bukanov, Jason Orendorff, Jesse Ruderman, and

Marcia Knous discovered multiple memory vulnerabilities in the browser

rendering engine. An attacker could use these to possibly execute arbitrary

code with the privileges of the user invoking Firefox. (CVE-2011-2995,

CVE-2011-2997)

Boris Zbarsky discovered that a frame named "location" could shadow the

window.location object unless a script in a page grabbed a reference to the

true object before the frame was created. This is in violation of the Same

Origin Policy. A malicious website could possibly use this to access

another website or the local file system. (CVE-2011-2999)

Ian Graham discovered that when multiple Location headers...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
  firefox                         7.0.1+build1+nobinonly-0ubuntu0.11.04.1

After a standard system update you need to restart Firefox to make all the
necessary changes.

References

https://ubuntu.com/security/notices/USN-1222-1

CVE-2011-2372, CVE-2011-2995, CVE-2011-2997, CVE-2011-2999,

CVE-2011-3000, CVE-2011-3001, CVE-2011-3002, CVE-2011-3003,

CVE-2011-3004, CVE-2011-3005, CVE-2011-3232

Severity
important
Lowest
Low
Medium
High
Critical

September 29, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.