Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Ubuntu 12.04 LTS: USN-1608-1 Moderate: Firefox Memory Corruption

ubuntu
Calendar Grey October 11, 2012
Scroller Ubuntu
Ubuntu Security Notice USN-1608-1 warns of critical Firefox vulnerabilities as of October 11, 2012, urging users to update for protection against exploits.
Several security issues were fixed in Firefox.

Summary

Several security issues were fixed in Firefox.

Software Description:

- firefox: Mozilla Open Source web browser

Details:

It was discovered that the browser engine used in Firefox contained a

memory corruption flaw. If a user were tricked into opening a specially

crafted web page, a remote attacker could cause Firefox to crash or

potentially execute arbitrary code as the user invoking the program.

(CVE-2012-4191)

It was discovered that Firefox allowed improper access to the Location

object. An attacker could exploit this to obtain sensitive information.

(CVE-2012-4192)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  firefox                         16.0.1+build1-0ubuntu0.12.04.1

Ubuntu 11.10:
  firefox                         16.0.1+build1-0ubuntu0.11.10.1

Ubuntu 11.04:
  firefox                         16.0.1+build1-0ubuntu0.11.04.1

Ubuntu 10.04 LTS:
  firefox                         16.0.1+build1-0ubuntu0.10.04.1

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1608-1

CVE-2012-4191, CVE-2012-4192, https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/1065285

Severity
important
Lowest
Low
Medium
High
Critical

October 11, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.