Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 12.04 LTS USN-1509-1 Critical: Firefox Exploit Threats

ubuntu
Calendar Grey July 17, 2012
Scroller Ubuntu
Tackling significant vulnerabilities in Firefox, USN-1509-2 boosts safety across various Ubuntu distributions, reducing multiple risks.
Several security issues were fixed in Firefox.

Summary

Several security issues were fixed in Firefox.

Software Description:

- firefox: Mozilla Open Source web browser

Details:

Benoit Jacob, Jesse Ruderman, Christian Holler, Bill McCloskey, Brian Smith,

Gary Kwong, Christoph Diehl, Chris Jones, Brad Lassey, and Kyle Huey discovered

memory safety issues affecting Firefox. If the user were tricked into opening a

specially crafted page, an attacker could possibly exploit these to cause a

denial of service via application crash, or potentially execute code with the

privileges of the user invoking Firefox. (CVE-2012-1948, CVE-2012-1949)

Mario Gomes discovered that the address bar may be incorrectly updated.

Drag-and-drop events in the address bar may cause the address of the previous

site to be displayed while a new page is loaded. An attacker could exploit this

to conduct phishing attacks. (CVE-2012-1950)

Abhishek Arya discovered four memory safety issues affecting Firefox. If the

user were tricked into opening a s...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  firefox                         14.0.1+build1-0ubuntu0.12.04.1

Ubuntu 11.10:
  firefox                         14.0.1+build1-0ubuntu0.11.10.1

Ubuntu 11.04:
  firefox                         14.0.1+build1-0ubuntu0.11.04.1

Ubuntu 10.04 LTS:
  firefox                         14.0.1+build1-0ubuntu0.10.04.1

When upgrading, users should be aware of the following:

- In Ubuntu 11.04, unity-2d users may lose the ability to view drop-down menus,
context menus, and perform drag-and-drop operations in Firefox. This is a known
issue being tracked in https://bugs.launchpad.net/ubuntu/+source/unity-2d/+bug/1020198 and may be fixed in a
later update.

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1509-1

CVE-2012-1948, CVE-2012-1949, CVE-2012-1950, CVE-2012-1951,

CVE-2012-1952, CVE-2012-1953, CVE-2012-1954, CVE-2012-1955,

CVE-2012-1957, CVE-2012-1958, CVE-2012-1959, CVE-2012-1960,

CVE-2012-1961, CVE-2012-1962, CVE-2012-1963, CVE-2012-1964,

CVE-2012-1965, CVE-2012-1966, CVE-2012-1967, https://bugs.launchpad.net/ubuntu/+source/unity-2d/+bug/1020198,

https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/1024562

Severity
critical
Lowest
Low
Medium
High
Critical

July 17, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.