Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update provides compatible ubufox and webfav packages for the latest
Firefox.
Software Description:
- ubufox: Ubuntu Firefox specific configuration defaults and apt support
- webfav: Firefox extension for saving web favorites (bookmarks)
Details:
USN-1355-1 fixed vulnerabilities in Firefox. This update provides updated
ubufox and webfav packages for use with the latest Firefox.
Original advisory details:
It was discovered that if a user chose to export their Firefox Sync key
the "Firefox Recovery Key.html" file is saved with incorrect permissions,
making the file contents potentially readable by other users.
(CVE-2012-0450)
Nicolas Gregoire and Aki Helin discovered that when processing a malformed
embedded XSLT stylesheet, Firefox can crash due to memory corruption. If
the user were tricked into opening a specially crafted page, an attacker
could exploit this to cause a denial of service via application crash, or
potentially execute code...
The problem can be corrected by updating your system to the following package versions: Ubuntu 10.10: xul-ext-ubufox 0.9.3-0ubuntu0.10.10.3 xul-ext-webfav 1.17-0ubuntu4.1 Ubuntu 10.04 LTS: xul-ext-ubufox 0.9.3-0ubuntu0.10.04.3 xul-ext-webfav 1.17-0ubuntu3.1 After a standard system update you need to restart Firefox to make all the necessary changes.
https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/923319
Get the latest Linux and open source security news straight to your inbox.