Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 477
Alerts This Week
Warning Icon 1 477

Ubuntu 12.04 LTS: USN-1463-1 Critical: Firefox Memory Safety Issues

ubuntu
Calendar Grey June 6, 2012
Scroller Ubuntu
Important vulnerabilities in Firefox addressed through Ubuntu updates, focusing on memory security and internet safety issues. Users encouraged to upgrade.
Several security issues were fixed in Firefox.

Summary

Several security issues were fixed in Firefox.

Software Description:

- firefox: Mozilla Open Source web browser

Details:

Jesse Ruderman, Igor Bukanov, Bill McCloskey, Christian Holler, Andrew

McCreight, Olli Pettay, Boris Zbarsky, and Brian Bondy discovered memory

safety issues affecting Firefox. If the user were tricked into opening a

specially crafted page, an attacker could possibly exploit these to cause a

denial of service via application crash, or potentially execute code with

the privileges of the user invoking Firefox. (CVE-2012-1937, CVE-2012-1938)

It was discovered that Mozilla's WebGL implementation exposed a bug in

certain NVIDIA graphics drivers. The impact of this issue has not been

disclosed at this time. (CVE-2011-3101)

Adam Barth discovered that certain inline event handlers were not being

blocked properly by the Content Security Policy's (CSP) inline-script

blocking feature. Web applications relying on this feature of CSP to

protect agai...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  firefox                         13.0+build1-0ubuntu0.12.04.1

Ubuntu 11.10:
  firefox                         13.0+build1-0ubuntu0.11.10.1

Ubuntu 11.04:
  firefox                         13.0+build1-0ubuntu0.11.04.1

Ubuntu 10.04 LTS:
  firefox                         13.0+build1-0ubuntu0.10.04.1

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1463-1

CVE-2011-3101, CVE-2012-0441, CVE-2012-1937, CVE-2012-1938,

CVE-2012-1940, CVE-2012-1941, CVE-2012-1944, CVE-2012-1945,

CVE-2012-1946, CVE-2012-1947, https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/1007495

Severity
critical
Lowest
Low
Medium
High
Critical

June 06, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.