Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in Firefox.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
It was discovered that if a user chose to export their Firefox Sync key
the "Firefox Recovery Key.html" file is saved with incorrect permissions,
making the file contents potentially readable by other users.
(CVE-2012-0450)
Nicolas Gregoire and Aki Helin discovered that when processing a malformed
embedded XSLT stylesheet, Firefox can crash due to memory corruption. If
the user were tricked into opening a specially crafted page, an attacker
could exploit this to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking Firefox.
(CVE-2012-0449)
It was discovered that memory corruption could occur during the decoding of
Ogg Vorbis files. If the user were tricked into opening a specially crafted
file, an attacker could exploit this to cause a denial of service via
application cra...
The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: firefox 10.0+build1-0ubuntu0.11.10.1 Ubuntu 11.04: firefox 10.0+build1-0ubuntu0.11.04.1 Ubuntu 10.10: firefox 10.0+build1-0ubuntu0.10.10.1 Ubuntu 10.04 LTS: firefox 10.0+build1-0ubuntu0.10.04.2 After a standard system update you need to restart Firefox to make all the necessary changes.
CVE-2011-3659, CVE-2012-0442, CVE-2012-0443, CVE-2012-0444,
CVE-2012-0445, CVE-2012-0446, CVE-2012-0447, CVE-2012-0449,
CVE-2012-0450, https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/923319
Get the latest Linux and open source security news straight to your inbox.