Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 11.10 Security Advisory: 1306-1 Critical Firefox Crash Issue

ubuntu
Calendar Grey January 6, 2012
Scroller Ubuntu
Recent bugs in Firefox may result in unexpected crashes or unauthorized code execution. Please update your Ubuntu installation for enhanced security.
Several security issues were fixed in Firefox.

Summary

Several security issues were fixed in Firefox.

Software Description:

- firefox: Mozilla Open Source web browser

Details:

Alexandre Poirot, Chris Blizzard, Kyle Huey, Scoobidiver, Christian Holler,

David Baron, Gary Kwong, Jim Blandy, Bob Clary, Jesse Ruderman, Marcia

Knous, and Rober Longson discovered several memory safety issues which

could possibly be exploited to crash Firefox or execute arbitrary code as

the user that invoked Firefox. (CVE-2011-3660)

Aki Helin discovered a crash in the YARR regular expression library that

could be triggered by javascript in web content. (CVE-2011-3661)

It was discovered that a flaw in the Mozilla SVG implementation could

result in an out-of-bounds memory access if SVG elements were removed

during a DOMAttrModified event handler. An attacker could potentially

exploit this vulnerability to crash Firefox. (CVE-2011-3658)

Mario Heiderich discovered it was possible to use SVG animation accessKey

events to detect key str...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  firefox                         9.0.1+build1-0ubuntu0.11.10.2

Ubuntu 11.04:
  firefox                         9.0.1+build1-0ubuntu0.11.04.1

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

CVE-2011-3658, CVE-2011-3660, CVE-2011-3661, CVE-2011-3663,

CVE-2011-3665, https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/906389

Severity
critical
Lowest
Low
Medium
High
Critical

January 06, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.