Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update provides compatible Mozvoikko packages for the latest Firefox.
Software Description:
- mozvoikko: Finnish spell-checker extension for Firefox
Details:
USN-1355-1 fixed vulnerabilities in Firefox. This update provides an
updated Mozvoikko package for use with the latest Firefox.
Original advisory details:
It was discovered that if a user chose to export their Firefox Sync key
the "Firefox Recovery Key.html" file is saved with incorrect permissions,
making the file contents potentially readable by other users.
(CVE-2012-0450)
Nicolas Gregoire and Aki Helin discovered that when processing a malformed
embedded XSLT stylesheet, Firefox can crash due to memory corruption. If
the user were tricked into opening a specially crafted page, an attacker
could exploit this to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking Firefox.
(CVE-2012-0449)
It was discovered that ...
The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: xul-ext-mozvoikko 2.0.1-0ubuntu0.11.10.1 Ubuntu 11.04: xul-ext-mozvoikko 2.0.1-0ubuntu0.11.04.1 Ubuntu 10.10: xul-ext-mozvoikko 2.0.1-0ubuntu0.10.10.1 Ubuntu 10.04 LTS: xul-ext-mozvoikko 2.0.1-0ubuntu0.10.04.1 After a standard system update you need to restart Firefox to make all the necessary changes.
https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/923319
Get the latest Linux and open source security news straight to your inbox.