Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
USN-1548-1 introduced a regression in Firefox.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
USN-1548-1 fixed vulnerabilities in Firefox. The new package caused a
regression in Private Browsing which could leak sites visited to the
browser cache. This update fixes the problem.
Original advisory details:
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Firefox. If the user were
tricked into opening a specially crafted page, an attacker could exploit
these to cause a denial of service via application crash, or potentially
execute code with the privileges of the user invoking Firefox.
(CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discovered multiple use-after-free vulnerabilities. If the
user were tricked into opening a specially crafted page, an attacker could
exploit the...
The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: firefox 15.0.1+build1-0ubuntu0.12.04.1 Ubuntu 11.10: firefox 15.0.1+build1-0ubuntu0.11.10.1 Ubuntu 11.04: firefox 15.0.1+build1-0ubuntu0.11.04.1 Ubuntu 10.04 LTS: firefox 15.0.1+build1-0ubuntu0.10.04.1 After a standard system update you need to restart Firefox to make all the necessary changes.
https://ubuntu.com/security/notices/USN-1548-2
https://ubuntu.com/security/notices/USN-1548-1
https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/1047667
Get the latest Linux and open source security news straight to your inbox.