Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Ubuntu 1600-2 Alerts: Security Flaws in Chrome and SQL Injection Threats

ubuntu
Calendar Grey October 9, 2012
Scroller Ubuntu
Several vulnerabilities discovered in Firefox pose risks to Ubuntu users; patches released to mitigate these concerns promptly.
Multiple security issues were fixed in Firefox.

Summary

Multiple security issues were fixed in Firefox.

Software Description:

- firefox: Mozilla Open Source web browser

Details:

Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others

discovered several memory corruption flaws in Firefox. If a user were

tricked into opening a specially crafted web page, a remote attacker could

cause Firefox to crash or potentially execute arbitrary code as the user

invoking the program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988,

CVE-2012-3989)

David Bloom and Jordi Chancel discovered that Firefox did not always

properly handle the select element. A remote attacker could exploit this

to conduct URL spoofing and clickjacking attacks. (CVE-2012-3984)

Collin Jackson discovered that Firefox did not properly follow the HTML5

specification for document.domain behavior. A remote attacker could exploit

this to conduct cross-site scripting (XSS) attacks via javascript

execution. (CVE-2012-3985)

Johnny Stenback di...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  firefox                         16.0+build1-0ubuntu0.12.04.1

Ubuntu 11.10:
  firefox                         16.0+build1-0ubuntu0.11.10.1

Ubuntu 11.04:
  firefox                         16.0+build1-0ubuntu0.11.04.1

Ubuntu 10.04 LTS:
  firefox                         16.0+build1-0ubuntu0.10.04.1

After a standard system update you need to restart Firefox to make all the
necessary changes.

References

https://ubuntu.com/security/notices/USN-1600-1

CVE-2012-3982, CVE-2012-3983, CVE-2012-3984, CVE-2012-3985,

CVE-2012-3986, CVE-2012-3988, CVE-2012-3989, CVE-2012-3990,

CVE-2012-3991, CVE-2012-3992, CVE-2012-3993, CVE-2012-3994,

CVE-2012-3995, CVE-2012-4179, CVE-2012-4180, CVE-2012-4181,

CVE-2012-4182, CVE-2012-4183, CVE-2012-4184, CVE-2012-4185,

CVE-2012-4186, CVE-2012-4187, CVE-2012-4188

Severity
critical
Lowest
Low
Medium
High
Critical

=========================================================================Ubuntu Security Notice USN-1600-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.